Releases1
Frequency
Last Release
Stars732
Digital Signage Player Software for Raspberry Pi, more details at

CVE History

CVEPublishedCVSS v3CVSS v2
4.3 MEDIUM4 MEDIUM

The web application component of piSignage before 2.6.4 allows a remote attacker (authenticated as a low-privilege user) to download arbitrary files from the Raspberry Pi via api/settings/log?file=../ path traversal. In other words, this issue is in the player API for log download.