GHSA-pgvh-p3g4-86jw
Dashboard / Vulnerabilities / GHSA-pgvh-p3g4-86jw
Summary: AVideo contains Command injection when embedding a video link
Details: Impact: An attacker could execute remote code on a system running wwbn/avideo Step to Reproduce: 1. Go to the `My Videos` tab https://demo.avideo.com/mvideos 2. Click "Embed a video link" Append a command to the url as a query string. eg. `?whoami` then click Save This issue has been resolved in commit `236228f15`
References: https://github.com/WWBN/AVideo/security/advisories/GHSA-pgvh-p3g4-86jw, https://nvd.nist.gov/vuln/detail/CVE-2023-30842, https://github.com/WWBN/AVideo/commit/236228f15a9a31be5a0e60f05dac043682e49a5e, https://github.com/WWBN/AVideo
Affected packages
Package
Name: wwbn/avideo
Purl: pkg:composer/wwbn/avideo
Affected ranges
Type: ECOSYSTEM
Events:
