AVideo contains Command injection when embedding a video link
Description
Published to the GitHub Advisory Database
Feb 2, 2023
Reviewed
Feb 2, 2023
Published by the National Vulnerability Database
Apr 25, 2023
Last updated
Nov 12, 2023
Impact:
An attacker could execute remote code on a system running wwbn/avideo
Step to Reproduce:
My Videos
tabhttps://demo.avideo.com/mvideos
Append a command to the url as a query string. eg.
?whoami
then click Save
This issue has been resolved in commit
236228f15
References