PT-2026-79541 · Avideo · Avideo
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
AVideo versions prior to commit 9c39d8c8
Description
An authentication bypass exists where the
deduplicateByEncoderQueueId() function returns video id hash credentials for any video based on the encoder queue id without verifying ownership. Subsequently, the useVideoHashOrLogin() function converts this hash into a passwordless login as the video owner. Users with upload permissions can retrieve an administrator's video id hash by omitting the videos id parameter, allowing them to use that hash in an unauthenticated request to obtain administrative session access and modify system configurations.Recommendations
Update AVideo to a version containing commit 9c39d8c8 or later.
Exploit
Fix
Missing Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Avideo