Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
AVideo - Arbitrary User Session Hijacking via Meet Plugin uploadRecordedVideo Endpoint
Vulnerability Description
AVideo through 29.0 contains an authorization bypass vulnerability in the Meet plugin's uploadRecordedVideo.json.php endpoint that derives the target users_id from the uploaded filename without verification. An attacker with knowledge of the Meet shared secret can craft a malicious file upload with a filename containing an arbitrary users_id to invoke passwordless User->login() and establish an authenticated session as any user including admin. Attackers can obtain the Meet shared secret through path-traversal vulnerabilities or timing attacks against checkToken.json.php, then POST a crafted file to uploadRecordedVideo.json.php with a filename like '1-anything.mp4' to hijack admin sessions and gain full account takeover.
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Vulnerability Type
认证机制不恰当
Vulnerability Title
WWBN AVideo 授权问题漏洞
Vulnerability Description
WWBN avideo是WWBN组织开源的一套视频内容管理系统。 WWBN AVideo 29.0及之前版本存在授权问题漏洞,该漏洞源于Meet插件中uploadRecordedVideo.json.php端点从上传文件名中提取目标users_id而未经验证,可能导致攻击者利用已知的Meet共享密钥,通过路径遍历或timing攻击获取共享密钥后,构造包含任意users_id的文件名上传,调用无密码User->login()建立已认证会话,进而劫持管理员会话并完全接管账户。
CVSS Information
N/A
Vulnerability Type
N/A