In Real Player 20.0.8.310, there is a DCP:// URI Remote...
Critical severity
Unreviewed
Published
Jun 4, 2022
to the GitHub Advisory Database
•
Updated Jan 27, 2023
Description
Published by the National Vulnerability Database
Jun 3, 2022
Published to the GitHub Advisory Database
Jun 4, 2022
Last updated
Jan 27, 2023
In Real Player 20.0.8.310, there is a DCP:// URI Remote Arbitrary Code Execution Vulnerability. This is an internal URL Protocol used by Real Player to reference a file that contains an URL. It is possible to inject script code to arbitrary domains. It is also possible to reference arbitrary local files.
References