vendor:
Centova Cast
by:
DroidU
7.5
CVSS
HIGH
Arbitrary File Download
CWE
Product Name: Centova Cast
Affected Version From: <=v3.2.11
Affected Version To: <=v3.2.11
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Debian 9, CentOS 7
2019
Centova Cast 3.2.11 – Arbitrary File Download
The Centova Cast 3.2.11 version is vulnerable to an arbitrary file download attack. An attacker can exploit this vulnerability to download arbitrary files from the server without authentication. This can lead to unauthorized access to sensitive information or system compromise.
Mitigation:
Upgrade to a patched version of Centova Cast. Ensure that proper access controls are in place to prevent unauthorized access to sensitive files.