CVE-2023-47624
13.12.2023, 21:15
Audiobookshelf is a self-hosted audiobook and podcast server. In versions 2.4.3 and prior, any user (regardless of their permissions) may be able to read files from the local file system due to a path traversal in the `/hls` endpoint. This issue may lead to Information Disclosure. As of time of publication, no patches are available.
Vendor | Product | Version |
---|---|---|
audiobookshelf | audiobookshelf | 𝑥 ≤ 2.4.3 |
𝑥
= Vulnerable software versions
References