GHSA-2mgx-226x-8pwv

    Dashboard / Vulnerabilities / GHSA-2mgx-226x-8pwv

    GHSA-2mgx-226x-8pwv

    Published: 24 May 2022Last Modified: 8 Nov 2023

    Summary: AVideo vulnerable to Improper Privilege Management

    Details: The import.json.php file before 8.9 for AVideo is vulnerable to a File Deletion vulnerability. This allows the deletion of configuration.php, causing certain privilege checks to not be in place, leading to privilege escalation to admin. Local File Inclusion may also leak credentials and important files. ### Patches Upgrade to version 8.9

    Affected packages

    Package

    Name: wwbn/avideo

    Purl: pkg:composer/wwbn/avideo

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -8.9

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-2mgx-226x-8pwv | CVE-DB