GHSA-pgvh-p3g4-86jwCriticalCVSS 9.6
AVideo contains Command injection when embedding a video link
🔗 CVE IDs covered (1)
📋 Description
Impact:
An attacker could execute remote code on a system running wwbn/avideo
Step to Reproduce:
- Go to the
My Videostab
https://demo.avideo.com/mvideos
- Click "Embed a video link"
Append a command to the url as a query string. eg. ?whoami
then click Save
This issue has been resolved in commit 236228f15
🎯 Affected products1
- composer/wwbn/avideo:< 12.4