Логотип exploitDog
bind:CVE-2025-34436
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-34436

Количество 2

Количество 2

nvd логотип

CVE-2025-34436

около 2 месяцев назад

AVideo versions prior to 20.1 allow any authenticated user to upload files into directories belonging to other users due to an insecure direct object reference. The upload functionality verifies authentication but does not enforce ownership checks.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-9p28-mpwc-hjwf

около 2 месяцев назад

AVideo versions prior to 20.0 allow any authenticated user to upload files into directories belonging to other users due to an insecure direct object reference. The upload functionality verifies authentication but does not enforce ownership checks.

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2025-34436

AVideo versions prior to 20.1 allow any authenticated user to upload files into directories belonging to other users due to an insecure direct object reference. The upload functionality verifies authentication but does not enforce ownership checks.

CVSS3: 8.8
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-9p28-mpwc-hjwf

AVideo versions prior to 20.0 allow any authenticated user to upload files into directories belonging to other users due to an insecure direct object reference. The upload functionality verifies authentication but does not enforce ownership checks.

CVSS3: 8.8
0%
Низкий
около 2 месяцев назад

Уязвимостей на страницу