Arbitrary File Read Vulnerability in WWBN AVideo Open Source Video Platform
CVE-2026-45731
6.9MEDIUM
What is CVE-2026-45731?
AVideo, an open-source video platform developed by WWBN, contains a vulnerability where the view/update.php file improperly handles the $_POST['updateFile'] parameter. This misconfiguration allows an authenticated administrator to exploit the system by specifying a relative path under the updatedb/ directory. Consequently, it enables the reading of arbitrary text files that are accessible to the web-server process, posing a significant security risk.
Affected Version(s)
AVideo <= 29.0
