VYPR
High severity7.5NVD Advisory· Published Mar 11, 2022· Updated Jun 17, 2026

CVE-2022-25216

CVE-2022-25216

Description

An absolute path traversal vulnerability allows a remote attacker to download any file on the Windows file system for which the user account running DVDFab 12 Player (recently renamed PlayerFab) has read-access, by means of an HTTP GET request to http://<IP_ADDRESS>:32080/download/<URL_ENCODED_PATH>.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

4
  • DVDFab/12 Player2 versions
    cpe:2.3:a:dvdfab:12_player:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:dvdfab:12_player:*:*:*:*:*:*:*:*range: >=6.2.10,<=6.2.11
    • (no CPE)
  • cpe:2.3:a:dvdfab:playerfab:*:*:*:*:*:*:*:*
    Range: >=7.0.0.0,<=7.0.0.5
  • DVDFab/DVDFab Playerdescription

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.