Executive brief
AVideo, an open-source video sharing platform, contains a vulnerability that allows an attacker to execute unauthorized commands on the server. By tricking a user into saving a specially crafted video link, an attacker could gain full control over the system, potentially leading to data theft or service disruption. Users should update to version 12.4 or later to resolve this issue.
Technical details
A command injection vulnerability exists in WWBN AVideo versions prior to 12.4 within the 'Embed a video link' functionality. The application fails to properly sanitize user-supplied URLs, allowing an attacker to append shell commands as query strings (e.g., '?whoami'). When a user saves the malicious link, the injected commands are executed on the underlying operating system. This can lead to full remote code execution (RCE). The issue was addressed in commit 236228f15 and officially patched in version 12.4.
Affected products
- WWBN AVideo < 12.4
Timeline
- 2023-01-31: disclosed: Vulnerability reported to vendor
- 2023-02-02: advisory: GitHub Advisory published
- 2023-04-25: other: NVD published CVE-2023-25313