Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 2

Количество 2

nvd логотип

CVE-2026-45731

4 месяца назад

WWBN AVideo is an open source video platform. In 29.0 and earlier, view/update.php reads $_POST['updateFile'] as a relative path under updatedb/ and passes it to PHP's file() for line-by-line execution as part of a database migration. An authenticated administrator can abuse this to read arbitrary text files reachable from the web-server process.

CVSS3: 4.9
EPSS: Низкий
github логотип

GHSA-3mjv-375j-6h92

4 месяца назад

AVideo: Authenticated Arbitrary File Read in view/update.php

CVSS3: 4.9
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2026-45731

WWBN AVideo is an open source video platform. In 29.0 and earlier, view/update.php reads $_POST['updateFile'] as a relative path under updatedb/ and passes it to PHP's file() for line-by-line execution as part of a database migration. An authenticated administrator can abuse this to read arbitrary text files reachable from the web-server process.

CVSS3: 4.9
0%
Низкий
4 месяца назад
github логотип
GHSA-3mjv-375j-6h92

AVideo: Authenticated Arbitrary File Read in view/update.php

CVSS3: 4.9
0%
Низкий
4 месяца назад

Уязвимостей на страницу