Impact:
An attacker could execute remote code on a system running wwbn/avideo
Step to Reproduce:
My Videos tabhttps://demo.avideo.com/mvideos
Append a command to the url as a query string. eg. ?whoami
then click Save
This issue has been resolved in commit 236228f15
{
"severity": "CRITICAL",
"nvd_published_at": "2023-04-25T22:15:09Z",
"github_reviewed": true,
"cwe_ids": [
"CWE-79"
],
"github_reviewed_at": "2023-02-02T01:32:42Z"
}