AVideo command injection vulnerability
CVE-2023-32073
Key Information:
Badges
What is CVE-2023-32073?
WWBN AVideo, an open-source video platform, is vulnerable to a command injection flaw in the CloneSite plugin. This vulnerability, present in versions 12.4 and earlier, allows attackers to execute arbitrary code remotely, effectively bypassing mitigations established for a previous vulnerability, CVE-2023-30854. The issue is addressed in a patch available as of commit 1df4af01f80d56ff2c4c43b89d0bac151e7fb6e3.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
AVideo <= 12.4
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V3.1
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
