Wwbn

Avideo

206 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.44%
  • Veröffentlicht 23.03.2026 16:29:47
  • Zuletzt bearbeitet 24.03.2026 17:01:02

WWBN AVideo is an open source video platform. In versions up to and including 26.0, an unauthenticated server-side request forgery vulnerability in `plugin/Live/test.php` allows any remote user to make the AVideo server send HTTP requests to arbitrar...

Exploit
  • EPSS 0.43%
  • Veröffentlicht 23.03.2026 16:28:20
  • Zuletzt bearbeitet 24.03.2026 18:08:01

WWBN AVideo is an open source video platform. In versions up to and including 26.0, the endpoint `plugin/Permissions/View/Users_groups_permissions/list.json.php` lacks any authentication or authorization check, allowing unauthenticated users to retri...

Exploit
  • EPSS 0.22%
  • Veröffentlicht 23.03.2026 16:24:52
  • Zuletzt bearbeitet 24.03.2026 18:11:11

WWBN AVideo is an open source video platform. In versions up to and including 26.0, the fix for CVE-2026-27568 (GHSA-rcqw-6466-3mv7) introduced a custom `ParsedownSafeWithLinks` class that sanitizes raw HTML `<a>` and `<img>` tags in comments, but ex...

Exploit
  • EPSS 0.23%
  • Veröffentlicht 23.03.2026 16:11:57
  • Zuletzt bearbeitet 24.03.2026 18:11:56

WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `view/forbiddenPage.php` and `view/warningPage.php` templates reflect the `$_REQUEST['unlockPassword']` parameter directly into an HTML `<input>` tag's attributes...

Exploit
  • EPSS 0.34%
  • Veröffentlicht 23.03.2026 15:52:33
  • Zuletzt bearbeitet 24.03.2026 18:17:24

WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `objects/import.json.php` endpoint accepts a user-controlled `fileURI` POST parameter with only a regex check that the value ends in `.mp4`. Unlike `objects/listF...

Exploit
  • EPSS 0.3%
  • Veröffentlicht 23.03.2026 15:25:27
  • Zuletzt bearbeitet 24.03.2026 17:47:58

WWBN AVideo is an open source video platform. In versions up to and including 26.0, AVideo's `_session_start()` function accepts arbitrary session IDs via the `PHPSESSID` GET parameter and sets them as the active PHP session. A session regeneration b...

Exploit
  • EPSS 0.25%
  • Veröffentlicht 23.03.2026 15:23:01
  • Zuletzt bearbeitet 24.03.2026 17:49:58

WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `createKeys()` function in the LoginControl plugin's PGP 2FA system generates 512-bit RSA keys, which have been publicly factorable since 1999. An attacker who ob...

Exploit
  • EPSS 0.47%
  • Veröffentlicht 23.03.2026 14:14:15
  • Zuletzt bearbeitet 24.03.2026 18:35:45

WWBN AVideo is an open source video platform. In versions up to and including 26.0, the RTMP `on_publish` callback at `plugin/Live/on_publish.php` is accessible without authentication. The `$_POST['name']` parameter (stream key) is interpolated direc...

Exploit
  • EPSS 0.61%
  • Veröffentlicht 23.03.2026 14:12:05
  • Zuletzt bearbeitet 24.03.2026 18:36:55

WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `aVideoEncoderChunk.json.php` endpoint is a completely standalone PHP script with no authentication, no framework includes, and no resource limits. An unauthentic...

Exploit
  • EPSS 2.06%
  • Veröffentlicht 23.03.2026 14:10:10
  • Zuletzt bearbeitet 24.03.2026 18:41:00

WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `sanitizeFFmpegCommand()` function in `plugin/API/standAlone/functions.php` is designed to prevent OS command injection in ffmpeg commands by stripping dangerous ...