← Terug naar overzicht

WWBN AVideo contains a critical path traversal vulnerability in the notify.ffmpeg.json.php script. Unauthenticated attackers can exploit the avideoRelativePath parameter to write files to arbitrary locations on the server. The vulnerability is compounded by a broken authentication mechanism where any previously issued ciphertext can be replayed as a notifyCode token. The token is decrypted but never validated, effectively allowing full authentication bypass. This enables attackers to write malicious files to the application root and its subdirectories. The combination of path traversal and authentication bypass makes this a high-severity issue. Successful exploitation could lead to remote code execution by writing web shells or overwriting critical application files. No authentication is required, significantly lowering the barrier for exploitation.

Affected products

  • WWBN AVideo

Related CVE's

  • CVE-2026-86189

Categories

  • Identity & Access
  • Web Technologies
  • Zero-Day Vulnerabilities