PT-2025-30679 · Wwbn · Avideo

·

CVE-2025-48732

·

Published

2025-07-24

·

Updated

2025-07-29

CVSS v3.1

7.3

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions WWBN AVideo version 14.4 WWBN AVideo dev master commit 8a8954ff
Description An incomplete blacklist in the .htaccess sample allows for arbitrary code execution via a specially crafted HTTP request. An attacker can request a .phar file to trigger this issue.
Recommendations Update WWBN AVideo to a version with a complete blacklist in the .htaccess sample. Avoid allowing requests for .phar files.

Exploit

Fix

Incomplete List of Disallowed Inputs

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-48732

Affected Products

Avideo