CVE-2023-25313: OS Command Injection
Impact:
An attacker could execute remote code on a system running wwbn/avideo
Step to Reproduce:
1. Go to the My Videos tab
https://demo.avideo.com/mvideos
2. Click "Embed a video link"
Append a command to the url as a query string. eg. ?whoami
then click Save
This issue has been resolved in commit 236228f15
Other sources
OS injection vulnerability in World Wide Broadcast Network AVideo version before 12.4, allows attackers to execute arbitrary code via the video link field to the Embed a video link feature.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-25313?
CVE-2023-25313 has a high severity rating due to its potential for remote code execution.
How do I fix CVE-2023-25313?
To fix CVE-2023-25313, update to version 12.4 or later of wwbn/avideo.
What systems are affected by CVE-2023-25313?
CVE-2023-25313 affects all versions of wwbn/avideo prior to 12.4.
What type of vulnerability is CVE-2023-25313?
CVE-2023-25313 is classified as a remote code execution vulnerability.
How can an attacker exploit CVE-2023-25313?
An attacker can exploit CVE-2023-25313 by appending a command to a video embed link in the 'My Videos' tab.