AVideo 中 插件存在一个认证缺失漏洞,允许未认证的攻击者通过发送带有计划广播标识符的精心构造的 POST 请求,将任意计划好的直播标记为失败状态。攻击者可以利用未受保护的 RTMP 回调端点,通过提供符合 模式的伪造流密钥,从而修改计划广播的状态字段,在无需凭证或授权的情况下静默取消任意计划直播。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet