{"dataType":"CVE_RECORD","dataVersion":"5.1","cveMetadata":{"state":"PUBLISHED","cveId":"CVE-2022-36243","assignerOrgId":"d3f162d7-5820-4c58-beef-03f43baaf8ad","assignerShortName":"ShopBeat","dateUpdated":"2025-01-13T20:56:36.011Z","dateReserved":"2022-07-18T00:00:00.000Z","datePublished":"2023-05-30T00:00:00.000Z"},"containers":{"cna":{"title":"Directory Traversal on Shop Beat Services","datePublic":"2023-05-23T00:00:00.000Z","providerMetadata":{"orgId":"d3f162d7-5820-4c58-beef-03f43baaf8ad","shortName":"ShopBeat","dateUpdated":"2023-05-30T00:00:00.000Z"},"descriptions":[{"lang":"en","value":"Shop Beat Solutions (pty) LTD Shop Beat Media Player 2.5.95 up to 3.2.57 is vulnerable to Directory Traversal via server.shopbeat.co.za. Information Exposure Through Directory Listing vulnerability in \"studio\" software of Shop Beat. This issue affects: Shop Beat studio studio versions prior to 3.2.57 on arm."}],"affected":[{"vendor":"Shop Beat","product":"studio","versions":[{"version":"studio","status":"affected","lessThan":"3.2.57","versionType":"custom"}],"platforms":["arm"]}],"references":[{"url":"https://www.shopbeat.co.za"}],"credits":[{"lang":"en","value":"Shop Beat thanks Emirates National Oil Company Limited (ENOC) LLC for the above discovery."}],"problemTypes":[{"descriptions":[{"type":"CWE","lang":"en","description":"CWE-548 Information Exposure Through Directory Listing","cweId":"CWE-548"}]}],"x_generator":{"engine":"Vulnogram 0.0.9"},"source":{"discovery":"INTERNAL"}},"adp":[{"providerMetadata":{"orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE","dateUpdated":"2024-08-03T10:00:04.272Z"},"title":"CVE Program Container","references":[{"url":"https://www.shopbeat.co.za","tags":["x_transferred"]}]},{"metrics":[{"cvssV3_1":{"scope":"UNCHANGED","version":"3.1","baseScore":5.3,"attackVector":"NETWORK","baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","integrityImpact":"NONE","userInteraction":"NONE","attackComplexity":"LOW","availabilityImpact":"NONE","privilegesRequired":"NONE","confidentialityImpact":"LOW"}},{"other":{"type":"ssvc","content":{"timestamp":"2025-01-13T20:56:00.626503Z","id":"CVE-2022-36243","options":[{"Exploitation":"none"},{"Automatable":"yes"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2025-01-13T20:56:36.011Z"}}]}}