Ecosyste.ms: Advisories
An open API service providing security vulnerability metadata for many open source software ecosystems.
Security Advisories: GSA_kwCzR0hTQS0ybWd4LTIyNngtOHB3ds4AAmob
AVideo vulnerable to Improper Privilege Management
The import.json.php file before 8.9 for AVideo is vulnerable to a File Deletion vulnerability. This allows the deletion of configuration.php, causing certain privilege checks to not be in place, leading to privilege escalation to admin. Local File Inclusion may also leak credentials and important files.
Patches
Upgrade to version 8.9
Permalink: https://github.com/advisories/GHSA-2mgx-226x-8pwvJSON: https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS0ybWd4LTIyNngtOHB3ds4AAmob
Source: GitHub Advisory Database
Origin: Unspecified
Severity: High
Classification: General
Published: almost 2 years ago
Updated: about 1 year ago
CVSS Score: 8.8
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Identifiers: GHSA-2mgx-226x-8pwv, CVE-2020-23489
References:
- https://nvd.nist.gov/vuln/detail/CVE-2020-23489
- https://github.com/WWBN/AVideo/commit/ecc5f40470bbafff231133f58db1df70f47bfb33
- https://cube01.io/blog/Avideo-Remote-Code-Execution.html
- https://github.com/WWBN/AVideo/security/advisories/GHSA-46px-7w93-j5mw
- https://github.com/WWBN/AVideo/issues/3117
- https://github.com/advisories/GHSA-2mgx-226x-8pwv
Blast Radius: 1.0
Affected Packages
packagist:wwbn/avideo
Dependent packages: 0Dependent repositories: 0
Downloads: 11 total
Affected Version Ranges: < 8.9
Fixed in: 8.9
All affected versions:
All unaffected versions: 11.1.1