vendor:
ProVision
by:
LiquidWorm
8.8
CVSS
HIGH
Authenticated File Disclosure Vulnerability
434
CWE
Product Name: ProVision
Affected Version From: 5.5
Affected Version To: 5.9.10
Patch Exists: YES
Related CWE: N/A
CPE: a:stvs:stvs_provision
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Ubuntu 14.04.3, nginx/1.12.1, nginx/1.4.6, nginx/1.1.19, nginx/0.7.65, nginx/0.3.61
2021
STVS ProVision 5.9.10 – File Disclosure (Authenticated)
The NVR software ProVision suffers from an authenticated arbitrary file disclosure vulnerability. Input passed through the files parameter in archive download script (archive.rb) is not properly verified before being used to download files. This can be exploited to disclose the contents of arbitrary and sensitive files.
Mitigation:
Ensure that user input is properly sanitized and validated before being used to download files.