HIGH
AVideo command injection vulnerability
Published May 12, 2023
8.8
HIGHCVSS 3.1
EPSS 6.46%
Description
WWBN AVideo is an open source video platform. In versions 12.4 and prior, a command injection vulnerability exists at `plugin/CloneSite/cloneClient.json.php` which allows Remote Code Execution if you CloneSite Plugin. This is a bypass to the fix for CVE-2023-30854, which affects WWBN AVideo up to version 12.3. This issue is patched in commit 1df4af01f80d56ff2c4c43b89d0bac151e7fb6e3.
Affected products
-
- Version <= 12.4StatusaffectedConstraints-
- Version
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (5)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-1451 Advisory
- https://github.com/WWBN/AVideo/commit/1df4af01f80d56ff2c4c43b89d0bac151e7fb6e3 x_refsource_MISCPatch
- https://github.com/WWBN/AVideo/security/advisories/GHSA-2mhh-27v7-3vcx x_refsource_CONFIRMExploitVendor Advisory
- https://github.com/advisories/GHSA-2mhh-27v7-3vcx Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2023-32073
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-1451 | Advisory | |
| https://github.com/WWBN/AVideo/commit/1df4af01f80d56ff2c4c43b89d0bac151e7fb6e3 | x_refsource_MISCPatch | |
| https://github.com/WWBN/AVideo/security/advisories/GHSA-2mhh-27v7-3vcx | x_refsource_CONFIRMExploitVendor Advisory | |
| https://github.com/advisories/GHSA-2mhh-27v7-3vcx | Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2023-32073 |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_M
Published May 12, 2023
Updated Jan 23, 2025
Reserved May 1, 2023
Link CVE-2023-32073
CISA Vulnrichment
Updated Jan 23, 2025
ENISA EUVD
EUVD-2023-1451 GHSA-2MHH-27V7-3VCX Assigner GitHub_M
Published May 12, 2023
Updated Jan 23, 2025
Exploited since n/a
Link EUVD-2023-1451