CVE-2023-32073: AVideo command injection vulnerability
Published May 12, 2023
·Updated
WWBN AVideo is an open source video platform. In versions 12.4 and prior, a command injection vulnerability exists at plugin/CloneSite/cloneClient.json.php which allows Remote Code Execution if you CloneSite Plugin. This is a bypass to the fix for CVE-2023-30854, which affects WWBN AVideo up to version 12.3. This issue is patched in commit 1df4af01f80d56ff2c4c43b89d0bac151e7fb6e3.
Affected Software
1 affected component
WWBN AVideo<=12.4
Remediation
Event History
May 12, 2023
CVE Published
via MITRE·01:34 PM
Data Sourced
via MITRE·01:34 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2023-32073?
CVE-2023-32073 has a severity score of 8.8 (High).
2
How can I exploit CVE-2023-32073 vulnerability?
The vulnerability in versions 12.4 and prior allows Remote Code Execution via command injection in the `cloneClient.json.php` file when using the CloneSite Plugin.
3
Is there a fix available for CVE-2023-32073?
At the time of writing, there may not be an official fix available. It is recommended to monitor official sources for updates.