PT-2026-27169 · Avideo · Avideo

Restriction

·

Publicado

2026-03-23

·

Atualizado

2026-03-25

·

CVE-2026-33647

CVSS v3.1

8.8

Alta

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions AVideo versions up to and including 26.0
Description AVideo is an open source video platform. The ImageGallery::saveFile() method validates uploaded file content using finfo MIME type detection but derives the saved filename extension from the user-supplied original filename without an allowlist check. An attacker can upload a polyglot file (valid JPEG magic bytes followed by PHP code) with a .php extension. The MIME check passes, but the file is saved as an executable .php file in a web-accessible directory, achieving Remote Code Execution. The vulnerable component is the ImageGallery::saveFile() function.
Recommendations Upgrade to commit 345a8d3ece0ad1e1b71a704c1579cbf885d8f3ae.

Exploit

Correção

RCE

Unrestricted File Upload

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-33647
GHSA-WXJW-PHJ6-G75W

Produtos afetados

Avideo