Huijietong Cloud Video Platform contains a path traversal...
High severity
Unreviewed
Published
Oct 15, 2025
to the GitHub Advisory Database
•
Updated Oct 15, 2025
Description
Published by the National Vulnerability Database
Oct 15, 2025
Published to the GitHub Advisory Database
Oct 15, 2025
Last updated
Oct 15, 2025
Huijietong Cloud Video Platform contains a path traversal vulnerability that allows an unauthenticated attacker can supply arbitrary file paths to the
fullPathparameter of the/fileDownload?action=downloadBackupFileendpoint and retrieve files from the server filesystem. VulnCheck has observed this vulnerability being targeted by the Rondo botnet.References