PT-2026-94103 · Avideo · Avideo
CVSS v4.0
5.3
Medium
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
AVideo versions prior to 29.0 (commit c3edcc274c389816d434acadac07ee78eaf330c1)
Description
Authenticated users can post comments on password-protected and group-restricted videos because the software fails to verify video access permissions in the
set api comment() function. This allows attackers to submit POST requests to the comment API endpoint using arbitrary video IDs to write comments on videos they are not authorized to watch.Recommendations
Update to a version later than 29.0 (commit c3edcc274c389816d434acadac07ee78eaf330c1).
Exploit
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Avideo