WWBN AVideo: Unauthenticated SQL Injection via JSON Request Bypass in objects/videos.json.php
43Vexday Risk Score
Corrige pronto. Ella tiene exploit funcional público.
ssvc Attendcvss 9.8epss 1.5%
de la publicación al arma0 días
Publicada en NVD6 mar
metasploit5 mar
probabilidad de explotación
1.5%top 28% de las CVE
explotación observada
noninguna fuente lo reporta
WWBN AVideo is an open source video platform. Prior to version 24.0, an unauthenticated SQL Injection vulnerability exists in AVideo within the objects/videos.json.php and objects/video.php components. The application fails to properly sanitize the catName parameter when it is supplied via a JSON-formatted POST request body. Because JSON input is parsed and merged into $_REQUEST after global security checks are executed, the payload bypasses the existing sanitization mechanisms. This issue has been patched in version 24.0.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Productos afectados
WWBN · AVideo