AVideo versions prior to 20.1 permit any authenticated user to upload comment images to videos owned by other users. The endpoint validates authentication but omits ownership checks, allowing attackers to perform unauthorized uploads to arbitrary video objects.
History

Fri, 19 Dec 2025 20:15:00 +0000

Type Values Removed Values Added
First Time appeared Wwnb
Wwnb avideo
CPEs cpe:2.3:a:wwnb:avideo:*:*:*:*:*:*:*:*
Vendors & Products Wwnb
Wwnb avideo

Fri, 19 Dec 2025 19:00:00 +0000

Type Values Removed Values Added
References

Fri, 19 Dec 2025 15:45:00 +0000

Type Values Removed Values Added
Description AVideo versions prior to 20.0 permit any authenticated user to upload comment images to videos owned by other users. The endpoint validates authentication but omits ownership checks, allowing attackers to perform unauthorized uploads to arbitrary video objects. AVideo versions prior to 20.1 permit any authenticated user to upload comment images to videos owned by other users. The endpoint validates authentication but omits ownership checks, allowing attackers to perform unauthorized uploads to arbitrary video objects.
Title AVideo < 20.0 IDOR Arbitrary Comment Image Upload AVideo < 20.1 IDOR Arbitrary Comment Image Upload

Thu, 18 Dec 2025 20:00:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:wwbn:avideo:*:*:*:*:*:*:*:*
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Thu, 18 Dec 2025 10:00:00 +0000

Type Values Removed Values Added
First Time appeared Wwbn
Wwbn avideo
Vendors & Products Wwbn
Wwbn avideo

Wed, 17 Dec 2025 21:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 17 Dec 2025 20:00:00 +0000

Type Values Removed Values Added
Description AVideo versions prior to 20.0 permit any authenticated user to upload comment images to videos owned by other users. The endpoint validates authentication but omits ownership checks, allowing attackers to perform unauthorized uploads to arbitrary video objects.
Title AVideo < 20.0 IDOR Arbitrary Comment Image Upload
Weaknesses CWE-639
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published: 2025-12-17T19:50:45.499Z

Updated: 2025-12-19T20:09:43.460Z

Reserved: 2025-04-15T19:15:22.601Z

Link: CVE-2025-34437

cve-icon Vulnrichment

Updated: 2025-12-17T20:24:07.349Z

cve-icon NVD

Status : Modified

Published: 2025-12-17T20:15:54.150

Modified: 2025-12-19T19:15:51.223

Link: CVE-2025-34437

cve-icon Redhat

No data.