CVE-2023-30854 Information

Description

AVideo is an open source video platform. Prior to version 12.4 an OS Command Injection vulnerability in an authenticated endpoint /plugin/CloneSite/cloneClient.json.php allows attackers to achieve Remote Code Execution. This issue is fixed in version 12.4.

Reference

https://github.com/WWBN/AVideo/security/advisories/GHSA-6vrj-ph27-qfp3

Share on: