CVE-2023-30854OS Command Injection in Avideo

Severity
8.8HIGHNVD
EPSS
70.2%
top 1.32%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedApr 28
Latest updateMay 12

Description

AVideo is an open source video platform. Prior to version 12.4, an OS Command Injection vulnerability in an authenticated endpoint `/plugin/CloneSite/cloneClient.json.php` allows attackers to achieve Remote Code Execution. This issue is fixed in version 12.4.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages3 packages

NVDwwbn/avideo< 12.4+1
Packagistwwbn/avideo< 12.4+1
CVEListV5wwbn/avideo12.4

🔴Vulnerability Details

4
OSV
WWBN AVideo command injection vulnerability2023-05-12
GHSA
WWBN AVideo command injection vulnerability2023-05-12
OSV
Remote code injection in wwbn/avideo2023-04-27
GHSA
Remote code injection in wwbn/avideo2023-04-27