PT-2026-94097 · Avideo · Clonesite+1
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
AVideo versions 29.0 and earlier
Description
The CloneSite plugin contains a stored OS command injection flaw. The issue occurs in
plugin/CloneSite/cloneClient.json.php where a stored SSH password is inserted into a command string using str replace without proper escaping. A single quote within the password allows an attacker to break out of the quoted string and execute arbitrary shell commands. The malicious password and a cloneSiteURL are written via the admin-only endpoint 'objects/pluginAddDataObject.json.php'. The Cross-Site Request Forgery (CSRF) defenses in isUntrustedRequest() and forbidIfIsUntrustedRequest() can be bypassed if the request appears to be loopback, such as when using a same-host TLS-terminating reverse proxy with $global['trustedProxies'] unset, or if an attacker-controlled application is co-hosted on the same hostname. Additionally, session cookies on HTTPS are issued with SameSite=None, facilitating cross-site POST requests. An unauthenticated remote attacker can trick an authenticated administrator into saving these malicious values, which are then executed by the system's crontab as the crontab owner, typically root or www-data.Recommendations
As a temporary workaround, disable the CloneSite plugin or remove its associated crontab entry to prevent the execution of injected commands.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Avideo
Clonesite