PT-2026-30988 · Wwbn · Avideo
Threalwinky
·
Published
2026-04-07
·
Updated
2026-04-08
·
CVE-2026-39369
CVSS v3.1
7.6
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
WWBN AVideo versions 26.0 and prior
Description
WWBN AVideo, an open source video platform, has an issue in the
aVideoEncoderReceiveImage.json.php file. An authenticated uploader can fetch attacker-controlled URLs, bypassing traversal scrubbing and exposing server-local files through the GIF poster storage path. This allows reading local files, such as /etc/passwd or application source files, and republishing their content through a public GIF media URL.Recommendations
Update to a version of WWBN AVideo later than 26.0.
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Avideo