RSS   Vulnerabilities for 'Avideo'   RSS

2022-04-05
 
CVE-2022-27462

CWE-79
 

 
Cross Site Scripting (XSS) vulnerability in objects/function.php in function getDeviceID in WWBN AVideo through 11.6, via the yptDevice parameter to view/include/head.php.

 
 
CVE-2022-27463

CWE-601
 

 
Open redirect vulnerability in objects/login.json.php in WWBN AVideo through 11.6, allows attackers to arbitrarily redirect users from a crafted url to the login page.

 
2021-02-01
 
CVE-2021-21286

CWE-863
 

 
AVideo Platform is an open-source Audio and Video platform. It is similar to a self-hosted YouTube. In AVideo Platform before version 10.2 there is an authorization bypass vulnerability which enables an ordinary user to get admin control. This is fixed in version 10.2. All queries now remove the pass hash and the recoverPass hash.

 


Copyright 2024, cxsecurity.com

 

Back to Top