Stored OS Command Injection Vulnerability in AVideo CloneSite Plugin
CVE-2026-92580
What is CVE-2026-92580?
The CloneSite plugin for AVideo versions up to 29.0 is vulnerable to stored OS command injection, specifically via SSH passwords. This vulnerability arises due to improper handling of user input when substituting the stored SSH password into command strings without escaping. An unauthenticated remote attacker can exploit this flaw by enticing an authenticated administrator to submit malicious data, which may include a harmful password or attacker-controlled CloneSite URL. If successful, the anomaly allows the execution of arbitrary shell commands without any additional administrative action, particularly affecting systems where the documented crontab entry is enabled. Exploitation can occur through various channels that bypass Cross-Site Request Forgery (CSRF) protections, potentially leading to severe security breaches.
Affected Version(s)
AVideo 0 <= 29.0
