PT-2025-51889 · Avideo · Avideo

·

CVE-2025-34437

·

Published

2025-12-17

·

Updated

2025-12-21

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions AVideo versions prior to 20.1
Description AVideo versions prior to 20.1 allow any authenticated user to upload comment images to videos owned by other users. The ''/comment images'' endpoint validates authentication but does not verify ownership, enabling unauthorized uploads to arbitrary video objects. The vulnerable parameter is video id.
Recommendations Update AVideo to version 20.1 or later.

Exploit

Fix

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-34437

Affected Products

Avideo