OS Command Injection in AVideo - CVE-2023-25313
Published: April 28, 2023
AVideo
World Wide Broadcast Network
Description
The vulnerability allows a remote attacker to execute arbitrary shell commands on the target system.
The vulnerability exists due to improper input validation when handling video links. A remote authenticated attacker can embed a video link, which contains an OS command and execute is on the system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.