Oryamdeune

#31980of 57,602
8.8Total CVSS
Vulnerabilities · 1
PT-2026-94097
8.8
2026-09-16
Avideo · Clonesite · CVE-2026-92580
**Name of the Vulnerable Software and Affected Versions** AVideo versions 29.0 and earlier **Description** The CloneSite plugin contains a stored OS command injection flaw. The issue occurs in `plugin/CloneSite/cloneClient.json.php` where a stored SSH password is inserted into a command string using `str replace` without proper escaping. A single quote within the password allows an attacker to break out of the quoted string and execute arbitrary shell commands. The malicious password and a `cloneSiteURL` are written via the admin-only endpoint 'objects/pluginAddDataObject.json.php'. The Cross-Site Request Forgery (CSRF) defenses in `isUntrustedRequest()` and `forbidIfIsUntrustedRequest()` can be bypassed if the request appears to be loopback, such as when using a same-host TLS-terminating reverse proxy with `$global['trustedProxies']` unset, or if an attacker-controlled application is co-hosted on the same hostname. Additionally, session cookies on HTTPS are issued with `SameSite=None`, facilitating cross-site POST requests. An unauthenticated remote attacker can trick an authenticated administrator into saving these malicious values, which are then executed by the system's crontab as the crontab owner, typically root or www-data. **Recommendations** As a temporary workaround, disable the CloneSite plugin or remove its associated crontab entry to prevent the execution of injected commands. At the moment, there is no information about a newer version that contains a fix for this vulnerability.