Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2vg4-rrx4-qcpq

Опубликовано: 04 апр. 2026
Источник: github
Github: Прошло ревью
CVSS3: 5.3

Описание

AVideo: Unauthenticated FFmpeg Remote Server Status Disclosure via check.ffmpeg.json.php

Summary

The plugin/API/check.ffmpeg.json.php endpoint probes the FFmpeg remote server configuration and returns connectivity status without any authentication. All sibling FFmpeg management endpoints (kill.ffmpeg.json.php, list.ffmpeg.json.php, ffmpeg.php) require User::isAdmin().

Details

The entire file at plugin/API/check.ffmpeg.json.php:

<?php $configFile = __DIR__.'/../../videos/configuration.php'; require_once $configFile; header('Content-Type: application/json'); $obj = testFFMPEGRemote(); die(json_encode($obj));

No User::isAdmin(), User::isLogged(), or any access control check exists.

Compare with sibling endpoints in the same directory:

  • kill.ffmpeg.json.php checks User::isAdmin()
  • list.ffmpeg.json.php checks User::isAdmin()

Proof of Concept

curl "https://your-avideo-instance.com/plugin/API/check.ffmpeg.json.php"

Returns information about whether the platform uses a standalone FFmpeg server and its current reachability.

Impact

Infrastructure reconnaissance revealing the encoding architecture. Limited direct impact but aids targeted attack planning.

Recommended Fix

Add an admin authentication check at plugin/API/check.ffmpeg.json.php:3, after require_once $configFile;:

if (!User::isAdmin()) { forbiddenPage('Admin only'); }

Found by aisafe.io

Пакеты

Наименование

wwbn/avideo

composer
Затронутые версииВерсия исправления

<= 26.0

Отсутствует

EPSS

Процентиль: 30%
0.0037
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-306

Связанные уязвимости

CVSS3: 5.3
nvd
4 месяца назад

WWBN AVideo is an open source video platform. In versions 26.0 and prior, the plugin/API/check.ffmpeg.json.php endpoint probes the FFmpeg remote server configuration and returns connectivity status without any authentication. All sibling FFmpeg management endpoints (kill.ffmpeg.json.php, list.ffmpeg.json.php, ffmpeg.php) require User::isAdmin().

EPSS

Процентиль: 30%
0.0037
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-306