GHSA-wj6r-53f5-q789
Dashboard / Vulnerabilities / GHSA-wj6r-53f5-q789
GHSA-wj6r-53f5-q789
Summary: Duplicate Advisory: AVideo contains Command injection when embedding a video link
Details: ## Duplicate Advisory This advisory has been withdrawn because it is a duplicate of GHSA-pgvh-p3g4-86jw. This link is maintained to preserve external references. ## Original Description Impact: An attacker could execute remote code on a system running wwbn/avideo Step to Reproduce: 1. Go to the `My Videos` tab https://demo.avideo.com/mvideos 2. Click "Embed a video link" Append a command to the url as a query string. eg. `?whoami` then click Save This issue has been resolved in commit `236228f15`
References: https://github.com/WWBN/AVideo/security/advisories/GHSA-pgvh-p3g4-86jw, https://nvd.nist.gov/vuln/detail/CVE-2023-25313
Affected packages
Package
Name: wwbn/avideo
Purl: pkg:composer/wwbn/avideo
Affected ranges
Type: ECOSYSTEM
Events:
