CVE-2023-49715
- EPSS 0.69%
- Veröffentlicht 10.01.2024 16:15:48
- Zuletzt bearbeitet 04.11.2025 19:16:09
A unrestricted php file upload vulnerability exists in the import.json.php temporary copy functionality of WWBN AVideo dev master commit 15fed957fb. A specially crafted HTTP request can lead to arbitrary code execution when chained with an LFI vulner...
CVE-2023-49599
- EPSS 0.29%
- Veröffentlicht 10.01.2024 16:15:48
- Zuletzt bearbeitet 04.11.2025 19:16:09
An insufficient entropy vulnerability exists in the salt generation functionality of WWBN AVideo dev master commit 15fed957fb. A specially crafted series of HTTP requests can lead to privilege escalation. An attacker can gather system information via...
CVE-2023-49589
- EPSS 0.25%
- Veröffentlicht 10.01.2024 16:15:48
- Zuletzt bearbeitet 04.11.2025 19:16:09
An insufficient entropy vulnerability exists in the userRecoverPass.php recoverPass generation functionality of WWBN AVideo dev master commit 15fed957fb. A specially crafted HTTP request can lead to an arbitrary user password recovery. An attacker ca...
CVE-2023-48730
- EPSS 0.48%
- Veröffentlicht 10.01.2024 16:15:47
- Zuletzt bearbeitet 04.11.2025 19:16:07
A cross-site scripting (xss) vulnerability exists in the navbarMenuAndLogo.php user name functionality of WWBN AVideo dev master commit 15fed957fb. A specially crafted HTTP request can lead to arbitrary Javascript execution. An attacker can get a use...
CVE-2023-48728
- EPSS 17.35%
- Veröffentlicht 10.01.2024 16:15:47
- Zuletzt bearbeitet 04.11.2025 19:16:07
A cross-site scripting (xss) vulnerability exists in the functiongetOpenGraph videoName functionality of WWBN AVideo 11.6 and dev master commit 3c6bb3ff. A specially crafted HTTP request can lead to arbitrary Javascript execution. An attacker can get...
CVE-2023-47862
- EPSS 0.88%
- Veröffentlicht 10.01.2024 16:15:47
- Zuletzt bearbeitet 04.11.2025 19:16:06
A local file inclusion vulnerability exists in the getLanguageFromBrowser functionality of WWBN AVideo dev master commit 15fed957fb. A specially crafted HTTP request can lead to arbitrary code execution. An attacker can send a series of HTTP requests...
CVE-2023-47861
- EPSS 0.34%
- Veröffentlicht 10.01.2024 16:15:47
- Zuletzt bearbeitet 04.11.2025 19:16:06
A cross-site scripting (xss) vulnerability exists in the channelBody.php user name functionality of WWBN AVideo 11.6 and dev master commit 15fed957fb. A specially crafted HTTP request can lead to arbitrary Javascript execution. An attacker can get a ...
CVE-2023-47171
- EPSS 0.31%
- Veröffentlicht 10.01.2024 16:15:47
- Zuletzt bearbeitet 04.11.2025 19:16:05
An information disclosure vulnerability exists in the aVideoEncoder.json.php chunkFile path functionality of WWBN AVideo 11.6 and dev master commit 15fed957fb. A specially crafted HTTP request can lead to arbitrary file read.
CVE-2023-32073
- EPSS 3.94%
- Veröffentlicht 12.05.2023 14:15:10
- Zuletzt bearbeitet 21.11.2024 08:02:39
WWBN AVideo is an open source video platform. In versions 12.4 and prior, a command injection vulnerability exists at `plugin/CloneSite/cloneClient.json.php` which allows Remote Code Execution if you CloneSite Plugin. This is a bypass to the fix for ...
CVE-2023-30860
- EPSS 3.6%
- Veröffentlicht 08.05.2023 19:15:12
- Zuletzt bearbeitet 21.11.2024 08:00:59
WWBN AVideo is an open source video platform. In AVideo prior to version 12.4, a normal user can make a Meeting Schedule where the user can invite another user in that Meeting, but it does not properly sanitize the malicious characters when creating ...