vendor:
dizqueTV
by:
Ahmed Said Saud Al-Busaidi
8.1
CVSS
CRITICAL
Remote Code Execution (RCE)
78
CWE
Product Name: dizqueTV
Affected Version From: 1.5.2003
Affected Version To: 1.5.2003
Patch Exists: NO
Related CWE:
CPE: a:vexorian:dizquetv:1.5.3
Platforms Tested: Linux
2024
dizqueTV 1.5.3 – Remote Code Execution (RCE)
dizqueTV version 1.5.3 is susceptible to a remote code execution vulnerability that allows attackers to execute unauthorized commands remotely. By manipulating the FFMPEG Executable Path in the settings to include a malicious command like "; cat /etc/passwd && echo 'poc'", an attacker can view the content of /etc/passwd.
Mitigation:
To mitigate this vulnerability, it is recommended to sanitize user inputs and validate configurations. Additionally, access controls should be implemented to restrict unauthorized access to sensitive functionalities.