PT-2019-17495 · Youphptube · Youphptube Encoder
Yuri Kramarz
·
Published
2019-10-25
·
Updated
2022-06-27
·
CVE-2019-5128
CVSS v3.1
10
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
YouPHPTube Encoder version 2.3
Description
A command injection issue has been discovered, which could allow an attacker to compromise the server. The issue is related to an unauthenticated command injection in the
base64Url parameter of the "/objects/getImageMP4.php" API endpoint. This could potentially be exploited by an attacker to execute arbitrary commands.Recommendations
For YouPHPTube Encoder version 2.3, consider disabling access to the
/objects/getImageMP4.php API endpoint or restricting the use of the base64Url parameter until a patch is available.Exploit
Fix
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Youphptube Encoder