PT-2026-27185 · Avideo · Avideo

Restriction

·

Publicado

2026-03-23

·

Atualizado

2026-03-25

·

CVE-2026-33681

CVSS v3.1

7.2

Alta

VetorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions AVideo versions up to and including 26.0
Description AVideo is an open source video platform. The objects/pluginRunDatabaseScript.json.php API endpoint accepts a name parameter via POST and passes it to the Plugin::getDatabaseFileName() function without proper path traversal sanitization. This allows an authenticated administrator, or an attacker via Cross-Site Request Forgery (CSRF), to traverse outside the plugin directory and execute the contents of any install/install.sql file on the filesystem as raw SQL queries against the application database.
Recommendations Update to a version beyond 26.0.

Exploit

Correção

Path traversal

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-33681
GHSA-3HWV-X8G3-9QPR

Produtos afetados

Avideo