CVE-2025-34437: AVideo < 20.1 IDOR Arbitrary Comment Image Upload
AVideo versions prior to 20.1 permit any authenticated user to upload comment images to videos owned by other users. The endpoint validates authentication but omits ownership checks, allowing attackers to perform unauthorized uploads to arbitrary video objects.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
AVideoto a version that resolves this vulnerability.Fixed in 20.1
Event History
Frequently Asked Questions
What is the severity of CVE-2025-34437?
CVE-2025-34437 is classified as a critical vulnerability due to its potential to allow unauthorized image uploads.
How do I fix CVE-2025-34437?
You can fix CVE-2025-34437 by upgrading AVideo to version 20.0 or higher.
Who is affected by CVE-2025-34437?
Any user of AVideo versions prior to 20.0 is affected by CVE-2025-34437.
What type of attack is possible with CVE-2025-34437?
CVE-2025-34437 allows an authenticated user to perform unauthorized uploads to videos owned by other users.
Are there any workarounds for CVE-2025-34437?
There are no known effective workarounds for CVE-2025-34437; updating to the latest version is recommended.