Path Traversal Flaw in Medialibrary Module by Huawei
CVE-2023-52953
6.2MEDIUM
Summary
A path traversal vulnerability exists in the Medialibrary module developed by Huawei, which can be exploited to gain unauthorized access to file system paths. This can lead to a compromise of both integrity and confidentiality, allowing attackers to read sensitive files outside the intended directories. Organizations using this module should take immediate action to mitigate the risk.
Affected Version(s)
EMUI 13.0.0
EMUI 12.0.0
HarmonyOS 3.0.0
References
CVSS V3.1
Score:
6.2
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Collectors
NVD DatabaseMitre Database