MiniDVBLinux 5.4 contains an arbitrary file disclosure vulnerability that allows attackers to read sensitive system files through the 'file' GET parameter. Attackers can exploit the about page by supplying file paths to disclose arbitrary file contents on the affected device.
References
| Link | Resource |
|---|---|
| https://www.exploit-db.com/exploits/51097 | Exploit Third Party Advisory VDB Entry |
| https://www.minidvblinux.de | Product |
| https://www.vulncheck.com/advisories/minidvblinux-arbitrary-file-read-vulnerability-via-about-page | Third Party Advisory |
| https://www.zeroscience.mk/en/vulnerabilities/ZSL-2022-5719.php | Exploit Third Party Advisory |
Configurations
History
No history.
Information
Published : 2025-12-09 21:15
Updated : 2025-12-19 19:20
NVD link : CVE-2023-53772
Mitre link : CVE-2023-53772
CVE.ORG link : CVE-2023-53772
JSON object : View
Products Affected
minidvblinux
- minidvblinux
CWE
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
