CVE-2023-30854
28.04.2023, 16:15
AVideo is an open source video platform. Prior to version 12.4, an OS Command Injection vulnerability in an authenticated endpoint `/plugin/CloneSite/cloneClient.json.php` allows attackers to achieve Remote Code Execution. This issue is fixed in version 12.4.
Vendor | Product | Version |
---|---|---|
wwbn | avideo | 𝑥 < 12.4 |
𝑥
= Vulnerable software versions