CVE Database
/

CVE-2024-13991

Back to search

CVE-2024-13991

Published: Oct 15, 2025

Modified: Nov 3, 2025

PUBLISHED

Description

Huijietong Cloud Video Platform contains a path traversal vulnerability that allows an unauthenticated attacker can supply arbitrary file paths to the `fullPath` parameter of the `/fileDownload?action=downloadBackupFile` endpoint and retrieve files from the server filesystem. VulnCheck has observed this vulnerability being exploited in the wild.

VendorProductVersions

Huijietong

Cloud Video Platform

affected
*

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now