PT-2023-23584 · Wwbn · Wwbn Avideo
Jmrcsnchz
·
Published
2023-05-12
·
Updated
2023-05-24
·
CVE-2023-32073
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
WWBN AVideo versions prior to 12.4
Description
A command injection issue exists in WWBN AVideo, allowing Remote Code Execution when the CloneSite Plugin is used. This issue is related to the
plugin/CloneSite/cloneClient.json.php endpoint. It is a bypass to a previous fix and is patched in a specific commit.Recommendations
For WWBN AVideo versions prior to 12.4, update to a version that includes the fix for this issue, specifically the commit 1df4af01f80d56ff2c4c43b89d0bac151e7fb6e3. As a temporary workaround, consider disabling the CloneSite Plugin until the issue is resolved.
Exploit
Fix
Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Wwbn Avideo