Filtered by vendor Zlmediakit Subscriptions
Filtered by product Zlmediakit Subscriptions
Total 4 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2023-31861 1 Zlmediakit 1 Zlmediakit 2025-01-16 7.5 High
ZLMediaKit 4.0 is vulnerable to Directory Traversal.
CVE-2024-27488 1 Zlmediakit 1 Zlmediakit 2024-11-21 9.8 Critical
Incorrect Access Control vulnerability in ZLMediaKit versions 1.0 through 8.0, allows remote attackers to escalate privileges and obtain sensitive information. The application system enables the http API interface by default and uses the secret parameter method to authenticate the http restful api interface, but the secret is hardcoded by default.
CVE-2023-39067 1 Zlmediakit 1 Zlmediakit 2024-11-21 6.1 Medium
Cross Site Scripting vulnerability in ZLMediaKiet v.4.0 and v.5.0 allows an attacker to execute arbitrary code via a crafted script to the URL.
CVE-2022-37237 1 Zlmediakit 1 Zlmediakit 2024-11-21 7.5 High
An attacker can send malicious RTMP requests to make the ZLMediaKit server crash remotely. Affected version is below commit 7d8b212a3c3368bc2f6507cb74664fc419eb9327.