Impact:
An attacker could execute remote code on a system running wwbn/avideo
Step to Reproduce:
My Videos
tabhttps://demo.avideo.com/mvideos
Append a command to the url as a query string. eg. ?whoami
then click Save
This issue has been resolved in commit 236228f15
{ "nvd_published_at": "2023-04-25T22:15:09Z", "cwe_ids": [ "CWE-79" ], "severity": "CRITICAL", "github_reviewed": true, "github_reviewed_at": "2023-02-02T01:32:42Z" }