PT-2025-51890 · Avideo · Avideo

Valentin Lobstein

·

Published

2025-12-17

·

Updated

2025-12-21

·

CVE-2025-34438

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions AVideo versions prior to 20.1
Description AVideo versions prior to 20.1 contain an insecure direct object reference issue. Users with upload permissions can modify the rotation metadata of any video. The ''/video/{id}'' endpoint verifies upload capability but does not enforce ownership or management rights for the targeted video. The vulnerable parameter is id.
Recommendations Update AVideo to version 20.1 or later.

Exploit

Fix

IDOR

Weakness Enumeration

Related Identifiers

CVE-2025-34438

Affected Products

Avideo