First published: Mon Nov 16 2020(Updated: )
The import.json.php file before 8.9 for Avideo is vulnerable to a File Deletion vulnerability. This allows the deletion of configuration.php, which leads to certain privilege checks not being in place, and therefore a user can escalate privileges to admin.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
WWBN AVideo | <8.9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-23489 is considered a medium severity vulnerability due to its potential for privilege escalation.
To fix CVE-2020-23489, update the AVideo software to version 8.9 or later.
AVideo versions before 8.9 are affected by CVE-2020-23489.
CVE-2020-23489 is a File Deletion vulnerability that can lead to privilege escalation.
Yes, CVE-2020-23489 can indirectly allow for remote code execution through privilege escalation.