First published: Mon Nov 16 2020(Updated: )
The import.json.php file before 8.9 for Avideo is vulnerable to a File Deletion vulnerability. This allows the deletion of configuration.php, which leads to certain privilege checks not being in place, and therefore a user can escalate privileges to admin.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
WWBN AVideo | <8.9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.