CVE-2023-43662 is an arbitrary file read vulnerability affecting ShokoServer, a media server for organizing anime. The `/api/Image/WithPath` endpoint, accessible without authentication, improperly handles the `serverImagePath` parameter, allowing unauthenticated attackers to read arbitrary files on the server. This vulnerability carries a high CVSS score of 8.6, indicating a critical risk due to its network-based attack vector, low attack complexity, and high confidentiality impact, especially when ShokoServer is installed with administrator privileges on Windows. While not currently listed in CISA's KEV catalog, a high-severity Nuclei template for Local File Inclusion (LFI) exists, and its EPSS score of 0.91785 suggests a high likelihood of exploitation. Community discussion and media coverage for this CVE are currently minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 4.2.2CPE matchmatch criteria | cpe:2.3:a:shokoanime:shokoserver:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.