An authenticated Remote Code Execution (RCE) vulnerability was identified in AVideo related to the plugin upload/import functionality.
The issue allowed an authenticated administrator to upload a specially crafted ZIP archive containing executable server-side files. Due to insufficient validation of extracted file contents, the archive was extracted directly into a web-accessible plugin directory, allowing arbitrary PHP code execution.
The system validated only the ZIP extension of uploaded plugin packages but did not enforce a strict allowlist of file types within the archive. Extracted files were placed directly in a web-accessible directory without preventing execution of server-side scripts.
An authenticated administrator could execute arbitrary code on the server, resulting in full system compromise, including:
Upgrade immediately to AVideo version 23 or later.
Version 23 introduces improved validation and secure handling of plugin extraction.
If upgrade is not immediately possible:
{
"cwe_ids": [
"CWE-434"
],
"github_reviewed": true,
"github_reviewed_at": "2026-03-02T20:56:52Z",
"nvd_published_at": "2026-03-06T04:16:08Z",
"severity": "CRITICAL"
}