PT-2025-51889 · Avideo · Avideo

Valentin Lobstein

·

Published

2025-12-17

·

Updated

2025-12-21

·

CVE-2025-34437

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions AVideo versions prior to 20.1
Description AVideo versions prior to 20.1 allow any authenticated user to upload comment images to videos owned by other users. The ''/comment images'' endpoint validates authentication but does not verify ownership, enabling unauthorized uploads to arbitrary video objects. The vulnerable parameter is video id.
Recommendations Update AVideo to version 20.1 or later.

Exploit

Fix

IDOR

Weakness Enumeration

Related Identifiers

CVE-2025-34437

Affected Products

Avideo