CVE-2025-34434: AVideo < 20.1 ImageGallery Plugin Unauthenticated File Upload and Deletion
AVideo versions prior to 20.1 with the ImageGallery plugin enabled is vulnerable to unauthenticated file upload and deletion. Plugin endpoints responsible for managing gallery images fail to enforce authentication checks and do not validate ownership, allowing unauthenticated attackers to upload or delete images associated with any image-based video.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
AVideoto a version that resolves this vulnerability.Fixed in 20.1 - Configuration
Disable the ImageGallery plugin in AVideo to prevent unauthenticated file upload and deletion.
AVideo ImageGallery plugin enabled = false
Event History
Frequently Asked Questions
What is the severity of CVE-2025-34434?
CVE-2025-34434 is considered a high-severity vulnerability due to its potential for unauthenticated file upload and deletion.
How do I fix CVE-2025-34434?
To fix CVE-2025-34434, upgrade to AVideo version 20.0 or later and disable the ImageGallery plugin if not in use.
What does CVE-2025-34434 affect?
CVE-2025-34434 affects AVideo versions prior to 20.0 that have the ImageGallery plugin enabled.
What type of attacks can be executed with CVE-2025-34434?
CVE-2025-34434 allows unauthenticated attackers to upload and delete files, potentially leading to further compromises.
How can I secure my AVideo installation against CVE-2025-34434?
To secure your AVideo installation against CVE-2025-34434, ensure you update to the latest version and review plugin configurations for proper authentication.