PT-2026-84537 · Avideo · Avideo

·

CVE-2026-84478

·

Published

2026-09-01

·

Updated

2026-09-03

CVSS v3.1

7.3

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions WWBN AVideo (affected versions not specified)
Description A path traversal issue exists in the 'get api login code' API endpoint. Unauthenticated attackers can delete arbitrary .log files by providing directory traversal sequences in the code parameter. This allows for the destruction of audit logs and the ability to probe for file existence on the server, resulting in both file deletion and information disclosure regarding the filesystem.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability. Avoid using the code parameter in the 'get api login code' API endpoint until the issue is resolved.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-84478
GHSA-WH69-GQMJ-RCQG

Affected Products

Avideo