PT-2026-94097 · Avideo · Clonesite+1

·

CVE-2026-92580

·

Published

2026-09-16

·

Updated

2026-09-19

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions AVideo versions 29.0 and earlier
Description The CloneSite plugin contains a stored OS command injection flaw. The issue occurs in plugin/CloneSite/cloneClient.json.php where a stored SSH password is inserted into a command string using str replace without proper escaping. A single quote within the password allows an attacker to break out of the quoted string and execute arbitrary shell commands. The malicious password and a cloneSiteURL are written via the admin-only endpoint 'objects/pluginAddDataObject.json.php'. The Cross-Site Request Forgery (CSRF) defenses in isUntrustedRequest() and forbidIfIsUntrustedRequest() can be bypassed if the request appears to be loopback, such as when using a same-host TLS-terminating reverse proxy with $global['trustedProxies'] unset, or if an attacker-controlled application is co-hosted on the same hostname. Additionally, session cookies on HTTPS are issued with SameSite=None, facilitating cross-site POST requests. An unauthenticated remote attacker can trick an authenticated administrator into saving these malicious values, which are then executed by the system's crontab as the crontab owner, typically root or www-data.
Recommendations As a temporary workaround, disable the CloneSite plugin or remove its associated crontab entry to prevent the execution of injected commands. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-92580
GHSA-G96R-PGR6-M7HH

Affected Products

Avideo
Clonesite