Wwbn Avideo vulnerabilities
163 known vulnerabilities affecting wwbn/avideo.
Total CVEs
163
CISA KEV
0
Public exploits
10
Exploited in wild
0
Severity breakdown
CRITICAL21HIGH64MEDIUM76LOW2
Vulnerabilities
Page 7 of 9
CVE-2023-49738HIGHCVSS 7.5v15fed957fbvdev master commit 15fed957fb2024-01-10
CVE-2023-49738 [HIGH] CWE-73 CVE-2023-49738: An information disclosure vulnerability exists in the image404Raw.php functionality of WWBN AVideo d
An information disclosure vulnerability exists in the image404Raw.php functionality of WWBN AVideo dev master commit 15fed957fb. A specially crafted HTTP request can lead to arbitrary file read.
nvd
CVE-2023-49589HIGHCVSS 8.8v15fed957fbvdev master commit 15fed957fb2024-01-10
CVE-2023-49589 [HIGH] CWE-640 CVE-2023-49589: An insufficient entropy vulnerability exists in the userRecoverPass.php recoverPass generation funct
An insufficient entropy vulnerability exists in the userRecoverPass.php recoverPass generation functionality of WWBN AVideo dev master commit 15fed957fb. A specially crafted HTTP request can lead to an arbitrary user password recovery. An attacker can send an HTTP request to trigger this vulnerability.
nvd
CVE-2023-49810MEDIUMCVSS 6.5v15fed957fbvdev master commit 15fed957fb2024-01-10
CVE-2023-49810 [MEDIUM] CWE-307 CVE-2023-49810: A login attempt restriction bypass vulnerability exists in the checkLoginAttempts functionality of W
A login attempt restriction bypass vulnerability exists in the checkLoginAttempts functionality of WWBN AVideo dev master commit 15fed957fb. A specially crafted HTTP request can lead to captcha bypass, which can be abused by an attacker to brute force user credentials. An attacker can send a series of HTTP requests to trigger this vulnerability.
ghsanvdosv
CVE-2023-48728MEDIUMCVSS 6.1PoCv3c6bb3ffv11.6+1 more2024-01-10
CVE-2023-48728 [MEDIUM] CWE-79 CVE-2023-48728: A cross-site scripting (xss) vulnerability exists in the functiongetOpenGraph videoName functionalit
A cross-site scripting (xss) vulnerability exists in the functiongetOpenGraph videoName functionality of WWBN AVideo 11.6 and dev master commit 3c6bb3ff. A specially crafted HTTP request can lead to arbitrary Javascript execution. An attacker can get a user to visit a webpage to trigger this vulnerability.
nvd
CVE-2023-50172MEDIUMCVSS 5.3v15fed957fbvdev master commit 15fed957fb2024-01-10
CVE-2023-50172 [MEDIUM] CWE-640 CVE-2023-50172: A recovery notification bypass vulnerability exists in the userRecoverPass.php captcha validation fu
A recovery notification bypass vulnerability exists in the userRecoverPass.php captcha validation functionality of WWBN AVideo dev master commit 15fed957fb. A specially crafted HTTP request can lead to the silent creation of a recovery pass code for any user.
ghsanvdosv
CVE-2023-49862MEDIUMCVSS 6.5vdev master commit 15fed957fb2024-01-10
CVE-2023-49862 [MEDIUM] CWE-73 CVE-2023-49862: An information disclosure vulnerability exists in the aVideoEncoderReceiveImage.json.php image uploa
An information disclosure vulnerability exists in the aVideoEncoderReceiveImage.json.php image upload functionality of WWBN AVideo dev master commit 15fed957fb. A specially crafted HTTP request can lead to arbitrary file read.This vulnerability is triggered by the `downloadURL_gifimage` parameter.
nvd
CVE-2023-49863MEDIUMCVSS 6.5vdev master commit 15fed957fb2024-01-10
CVE-2023-49863 [MEDIUM] CWE-73 CVE-2023-49863: An information disclosure vulnerability exists in the aVideoEncoderReceiveImage.json.php image uploa
An information disclosure vulnerability exists in the aVideoEncoderReceiveImage.json.php image upload functionality of WWBN AVideo dev master commit 15fed957fb. A specially crafted HTTP request can lead to arbitrary file read.This vulnerability is triggered by the `downloadURL_webpimage` parameter.
nvd
CVE-2023-47171MEDIUMCVSS 6.5v11.6v15fed957fb+1 more2024-01-10
CVE-2023-47171 [MEDIUM] CWE-73 CVE-2023-47171: An information disclosure vulnerability exists in the aVideoEncoder.json.php chunkFile path function
An information disclosure vulnerability exists in the aVideoEncoder.json.php chunkFile path functionality of WWBN AVideo 11.6 and dev master commit 15fed957fb. A specially crafted HTTP request can lead to arbitrary file read.
nvd
CVE-2023-49864MEDIUMCVSS 6.5vdev_master_commit_15fed957fbvdev master commit 15fed957fb2024-01-10
CVE-2023-49864 [MEDIUM] CWE-73 CVE-2023-49864: An information disclosure vulnerability exists in the aVideoEncoderReceiveImage.json.php image uploa
An information disclosure vulnerability exists in the aVideoEncoderReceiveImage.json.php image upload functionality of WWBN AVideo dev master commit 15fed957fb. A specially crafted HTTP request can lead to arbitrary file read.This vulnerability is triggered by the `downloadURL_image` parameter.
nvd
CVE-2023-48730MEDIUMCVSS 5.4v15fed957fbvdev master commit 15fed957fb2024-01-10
CVE-2023-48730 [MEDIUM] CWE-79 CVE-2023-48730: A cross-site scripting (xss) vulnerability exists in the navbarMenuAndLogo.php user name functionali
A cross-site scripting (xss) vulnerability exists in the navbarMenuAndLogo.php user name functionality of WWBN AVideo dev master commit 15fed957fb. A specially crafted HTTP request can lead to arbitrary Javascript execution. An attacker can get a user to visit a webpage to trigger this vulnerability.
nvd
CVE-2023-47861MEDIUMCVSS 5.4v11.6v15fed957fb+1 more2024-01-10
CVE-2023-47861 [MEDIUM] CWE-79 CVE-2023-47861: A cross-site scripting (xss) vulnerability exists in the channelBody.php user name functionality of
A cross-site scripting (xss) vulnerability exists in the channelBody.php user name functionality of WWBN AVideo 11.6 and dev master commit 15fed957fb. A specially crafted HTTP request can lead to arbitrary Javascript execution. An attacker can get a user to visit a webpage to trigger this vulnerability.
nvd
CVE-2023-32073HIGHCVSS 8.8≤ 12.42023-05-12
CVE-2023-32073 [HIGH] CVE-2023-32073: WWBN AVideo is an open source video platform. In versions 12.4 and prior, a command injection vulner
WWBN AVideo is an open source video platform. In versions 12.4 and prior, a command injection vulnerability exists at `plugin/CloneSite/cloneClient.json.php` which allows Remote Code Execution if you CloneSite Plugin. This is a bypass to the fix for CVE-2023-30854, which affects WWBN AVideo up to version 12.3. This issue is patched in commit 1df4af01f80d56ff2
ghsanvdosv
CVE-2023-30860MEDIUMCVSS 5.4fixed in 12.42023-05-08
CVE-2023-30860 [MEDIUM] CWE-79 CVE-2023-30860: WWBN AVideo is an open source video platform. In AVideo prior to version 12.4, a normal user can mak
WWBN AVideo is an open source video platform. In AVideo prior to version 12.4, a normal user can make a Meeting Schedule where the user can invite another user in that Meeting, but it does not properly sanitize the malicious characters when creating a Meeting Room. This allows attacker to insert malicious scripts. Since any USER including the ADMIN c
ghsanvdosv
CVE-2023-30854HIGHCVSS 8.8fixed in 12.4≤ 12.42023-04-28
CVE-2023-30854 [HIGH] CWE-78 CVE-2023-30854: AVideo is an open source video platform. Prior to version 12.4, an OS Command Injection vulnerabilit
AVideo is an open source video platform. Prior to version 12.4, an OS Command Injection vulnerability in an authenticated endpoint `/plugin/CloneSite/cloneClient.json.php` allows attackers to achieve Remote Code Execution. This issue is fixed in version 12.4.
ghsanvdosv
CVE-2023-25313CRITICALCVSS 9.8fixed in 12.42023-04-25
CVE-2023-25313 [CRITICAL] CWE-78 CVE-2023-25313: OS injection vulnerability in World Wide Broadcast Network AVideo version before 12.4, allows attack
OS injection vulnerability in World Wide Broadcast Network AVideo version before 12.4, allows attackers to execute arbitrary code via the video link field to the Embed a video link feature.
ghsanvdosv
CVE-2023-25314MEDIUMCVSS 6.1fixed in 12.42023-04-25
CVE-2023-25314 [MEDIUM] CWE-79 CVE-2023-25314: Cross Site Scripting (XSS) vulnerability in World Wide Broadcast Network AVideo before 12.4, allows
Cross Site Scripting (XSS) vulnerability in World Wide Broadcast Network AVideo before 12.4, allows attackers to gain sensitive information via the success parameter to /user.
nvd
CVE-2022-30547CRITICALCVSS 9.9v11.6vdev master commit 3f7c03642022-08-22
CVE-2022-30547 [CRITICAL] CWE-22 CVE-2022-30547: A directory traversal vulnerability exists in the unzipDirectory functionality of WWBN AVideo 11.6 a
A directory traversal vulnerability exists in the unzipDirectory functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. A specially-crafted HTTP request can lead to arbitrary command execution. An attacker can send an HTTP request to trigger this vulnerability.
nvd
CVE-2022-26842CRITICALCVSS 9.6v11.6vdev master commit 3f7c03642022-08-22
CVE-2022-26842 [CRITICAL] CWE-79 CVE-2022-26842: A reflected cross-site scripting (xss) vulnerability exists in the charts tab selection functionalit
A reflected cross-site scripting (xss) vulnerability exists in the charts tab selection functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. A specially-crafted HTTP request can lead to arbitrary Javascript execution. An attacker can get an authenticated user to send a crafted HTTP request to trigger this vulnerability.
nvd
CVE-2022-28712CRITICALCVSS 9.0v11.6vdev master commit 3f7c03642022-08-22
CVE-2022-28712 [CRITICAL] CWE-79 CVE-2022-28712: A cross-site scripting (xss) vulnerability exists in the videoAddNew functionality of WWBN AVideo 11
A cross-site scripting (xss) vulnerability exists in the videoAddNew functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. A specially-crafted HTTP request can lead to arbitrary Javascript execution. An attacker can get an authenticated user to send a crafted HTTP request to trigger this vulnerability.
nvd
CVE-2022-32777HIGHCVSS 7.5v11.6vdev master commit 3f7c03642022-08-22
CVE-2022-32777 [HIGH] CWE-732 CVE-2022-32777: An information disclosure vulnerability exists in the cookie functionality of WWBN AVideo 11.6 and d
An information disclosure vulnerability exists in the cookie functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. The session cookie and the pass cookie miss the HttpOnly flag, making them accessible via JavaScript. The session cookie also misses the secure flag, which allows the session cookie to be leaked over non-HTTPS connections. Thi
nvd