OS Command Injection in AVideo - CVE-2023-25313

 

OS Command Injection in AVideo - CVE-2023-25313

Published: April 28, 2023


Vulnerability identifier: #VU75564
CSH Severity: High
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-25313
CWE-ID: CWE-78
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary shell commands on the target system.

The vulnerability exists due to improper input validation when handling video links. A remote authenticated attacker can embed a video link, which contains an OS command and execute is on the system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


Affected software

AVideo

How to mitigate CVE-2023-25313

Install updates from vendor's website.

AVideo - update to 12.4

External References

Related Security Bulletins