PT-2023-23584 · Wwbn · Wwbn Avideo

·

CVE-2023-32073

·

Published

2023-05-12

·

Updated

2023-05-24

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions WWBN AVideo versions prior to 12.4
Description A command injection issue exists in WWBN AVideo, allowing Remote Code Execution when the CloneSite Plugin is used. This issue is related to the plugin/CloneSite/cloneClient.json.php endpoint. It is a bypass to a previous fix and is patched in a specific commit.
Recommendations For WWBN AVideo versions prior to 12.4, update to a version that includes the fix for this issue, specifically the commit 1df4af01f80d56ff2c4c43b89d0bac151e7fb6e3. As a temporary workaround, consider disabling the CloneSite Plugin until the issue is resolved.

Exploit

Fix

Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2023-32073
GHSA-2MHH-27V7-3VCX

Affected Products

Wwbn Avideo