Vulnerability CVE-2023-30854


Published: 2023-04-28

Description:
AVideo is an open source video platform. Prior to version 12.4, an OS Command Injection vulnerability in an authenticated endpoint `/plugin/CloneSite/cloneClient.json.php` allows attackers to achieve Remote Code Execution. This issue is fixed in version 12.4.

Type:

CWE-78

(Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') )

 References:
https://github.com/WWBN/AVideo/security/advisories/GHSA-6vrj-ph27-qfp3

Copyright 2026, cxsecurity.com

 

Back to Top