An incomplete blacklist exists in the .htaccess sample of WWBN AVideo 14.4 and dev master commit 8a8954ff. A specially crafted HTTP request can lead to a arbitrary code execution. An attacker can request a .phar file to trigger this vulnerability.
{ "versions": [ { "introduced": "0" }, { "last_affected": "14.4" } ] }
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-48732.json"