PT-2026-34063 · Avideo · Avideo
Published
2026-04-14
·
Updated
2026-04-27
·
CVE-2026-40909
CVSS v3.1
8.7
High
| Vector | AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
AVideo versions prior to 29.0
Description
The locale save endpoint "locale/save.php" constructs a file path by directly concatenating the
flag parameter into the path without sanitization. The code parameter is then written to that path using the fwrite() function. An attacker with administrative privileges, or a user capable of performing a Cross-Site Request Forgery (CSRF) attack against an administrator, can use path traversal to write arbitrary .php files to any writable location on the filesystem, leading to Remote Code Execution (RCE), which is the ability to execute arbitrary commands on the target machine.Recommendations
Update to a version later than 29.0.
As a temporary workaround, restrict access to the "locale/save.php" endpoint.
Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Avideo