GHSA-2mgx-226x-8pwv

Source
https://github.com/advisories/GHSA-2mgx-226x-8pwv
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-2mgx-226x-8pwv/GHSA-2mgx-226x-8pwv.json
Aliases
Published
2022-05-24T17:34:15Z
Modified
2023-11-08T04:03:06.035510Z
Details

The import.json.php file before 8.9 for AVideo is vulnerable to a File Deletion vulnerability. This allows the deletion of configuration.php, causing certain privilege checks to not be in place, leading to privilege escalation to admin. Local File Inclusion may also leak credentials and important files.

Patches

Upgrade to version 8.9

References

Affected packages

Packagist / wwbn/avideo

Package

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0The exact introduced commit is unknown
Fixed
8.9