Skip to main content

Vendor/product archive

wwbn / avideo CVEs

Beta · best-effort

190 CVEs tagged to wwbn / avideo25 Critical, 78 High, 85 Medium, 2 Low, 0 Unrated.

CVE-2023-49715

Published Jan 10, 2024

A unrestricted php file upload vulnerability exists in the import.json.php temporary copy functionality of WWBN AVideo dev master commit 15fed957fb. A specially crafted HTTP reque…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-49599

Published Jan 10, 2024

An insufficient entropy vulnerability exists in the salt generation functionality of WWBN AVideo dev master commit 15fed957fb. A specially crafted series of HTTP requests can lead…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-49589

Published Jan 10, 2024

An insufficient entropy vulnerability exists in the userRecoverPass.php recoverPass generation functionality of WWBN AVideo dev master commit 15fed957fb. A specially crafted HTTP…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-48730

Published Jan 10, 2024

A cross-site scripting (xss) vulnerability exists in the navbarMenuAndLogo.php user name functionality of WWBN AVideo dev master commit 15fed957fb. A specially crafted HTTP reques…

CVSS 8.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-48728

Published Jan 10, 2024

A cross-site scripting (xss) vulnerability exists in the functiongetOpenGraph videoName functionality of WWBN AVideo 11.6 and dev master commit 3c6bb3ff. A specially crafted HTTP…

CVSS 9.6 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-47862

Published Jan 10, 2024

A local file inclusion vulnerability exists in the getLanguageFromBrowser functionality of WWBN AVideo dev master commit 15fed957fb. A specially crafted HTTP request can lead to a…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-47861

Published Jan 10, 2024

A cross-site scripting (xss) vulnerability exists in the channelBody.php user name functionality of WWBN AVideo 11.6 and dev master commit 15fed957fb. A specially crafted HTTP req…

CVSS 9.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-47171

Published Jan 10, 2024

An information disclosure vulnerability exists in the aVideoEncoder.json.php chunkFile path functionality of WWBN AVideo 11.6 and dev master commit 15fed957fb. A specially crafted…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-32073

Published May 12, 2023

WWBN AVideo is an open source video platform. In versions 12.4 and prior, a command injection vulnerability exists at `plugin/CloneSite/cloneClient.json.php` which allows Remote C…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-30860

Published May 8, 2023

WWBN AVideo is an open source video platform. In AVideo prior to version 12.4, a normal user can make a Meeting Schedule where the user can invite another user in that Meeting, bu…

CVSS 8.0 · High
Vendor/product tagsBeta · best-effort

CVE-2023-30854

Published Apr 28, 2023

AVideo is an open source video platform. Prior to version 12.4, an OS Command Injection vulnerability in an authenticated endpoint `/plugin/CloneSite/cloneClient.json.php` allows…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-25314

Published Apr 25, 2023

Cross Site Scripting (XSS) vulnerability in World Wide Broadcast Network AVideo before 12.4, allows attackers to gain sensitive information via the success parameter to /user.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-25313

Published Apr 25, 2023

OS injection vulnerability in World Wide Broadcast Network AVideo version before 12.4, allows attackers to execute arbitrary code via the video link field to the Embed a video lin…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2022-34652

Published Aug 22, 2022

A sql injection vulnerability exists in the ObjectYPT functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. A specially-crafted HTTP request can lead to a SQL injectio…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2022-33149

Published Aug 22, 2022

A sql injection vulnerability exists in the ObjectYPT functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. A specially-crafted HTTP request can lead to a SQL injectio…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2022-33148

Published Aug 22, 2022

A sql injection vulnerability exists in the ObjectYPT functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. A specially-crafted HTTP request can lead to a SQL injectio…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2022-33147

Published Aug 22, 2022

A sql injection vulnerability exists in the ObjectYPT functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. A specially-crafted HTTP request can lead to a SQL injectio…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2022-32778

Published Aug 22, 2022

An information disclosure vulnerability exists in the cookie functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. The session cookie and the pass cookie miss the Http…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-32777

Published Aug 22, 2022

An information disclosure vulnerability exists in the cookie functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. The session cookie and the pass cookie miss the Http…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-32772

Published Aug 22, 2022

A cross-site scripting (xss) vulnerability exists in the footer alerts functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. A specially-crafted HTTP request can lead…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-32771

Published Aug 22, 2022

A cross-site scripting (xss) vulnerability exists in the footer alerts functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. A specially-crafted HTTP request can lead…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-32770

Published Aug 22, 2022

A cross-site scripting (xss) vulnerability exists in the footer alerts functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. A specially-crafted HTTP request can lead…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-32769

Published Aug 22, 2022

Multiple authentication bypass vulnerabilities exist in the objects id handling functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. A specially-crafted HTTP request…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-32768

Published Aug 22, 2022

Multiple authentication bypass vulnerabilities exist in the objects id handling functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. A specially-crafted HTTP request…

CVSS 4.2 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-32761

Published Aug 22, 2022

An information disclosure vulnerability exists in the aVideoEncoderReceiveImage functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. A specially-crafted HTTP request…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort
Showing 151-175 of 190 CVEsPage 7 of 8