CVE-2026-45731

Published
View on NVD ↗
CVSS v3
4.9
MEDIUM
CVSS v2
N/A
Affected
1
PROJECT

Description

WWBN AVideo is an open source video platform. In 29.0 and earlier, view/update.php reads $_POST['updateFile'] as a relative path under updatedb/ and passes it to PHP's file() for line-by-line execution as part of a database migration. An authenticated administrator can abuse this to read arbitrary text files reachable from the web-server process.

Create Your Own Broadcast Network With AVideo Platform Open-Source. OAVP OVP
GitHubGitHub
2.1K