PT-2026-84992 · Avideo · Avideo
CVSS v3.1
8.1
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
AVideo versions prior to commit c91b5975d
Description
An issue exists in the 'stopLive.php' endpoint due to missing token validation and unsanitized concatenation of the
key parameter. This allows for cross-site request forgery (CSRF) and path traversal, where an attacker can trigger the recursive deletion of directories. For example, by crafting an image tag with a payload such as key=../../videos, an attacker can delete the videos directory if an administrator visits a malicious page.Recommendations
Update AVideo to a version beyond commit c91b5975d.
As a temporary mitigation, restrict access to the 'stopLive.php' endpoint or avoid using the
key parameter until the update is applied.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Avideo