CVE-2022-25568

Published
View on NVD ↗
CVSS v3
7.5
HIGH
CVSS v2
4.3
MEDIUM
Affected
1
PROJECT

Description

MotionEye v0.42.1 and below allows attackers to access sensitive information via a GET request to /config/list. To exploit this vulnerability, a regular user password must be unconfigured.

A web frontend for the motion daemon.
GitHubGitHub
4.6K