Impact
VideoFlow Digital Video Protection DVP 2.10 contains an authenticated directory traversal vulnerability that lets attackers in possession of valid credentials inject path traversal sequences into an ID parameter used by several download scripts. This flaw permits reading arbitrary files on the server, including sensitive files such as /etc/passwd. As a result, information that should remain confidential—system configuration and user credentials—may be disclosed. The weakness is identified as CWE‑22.
Affected Systems
The affected product is VideoFlow Digital Video Protection DVP 2.10 from VideoFlow Ltd. No other versions are explicitly listed as vulnerable.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity vulnerability that requires authentication on the target system. The EPSS score of < 1% indicates a very low probability that the vulnerability is being exploited in the wild, and the vulnerability is not listed in the CISA KEV. Based on the description, the likely attack vector is via an authenticated user submitting crafted download requests; the attacker needs valid credentials and can then acquire arbitrary files which may contain credentials or system configuration data.
OpenCVE Enrichment