WWBN AVideo
cpe:2.3:a:wwbn:avideo:*:*:*:*:*:*:*
- < 20.0
A vulnerability in AVideo versions prior to 20.0 allows authenticated users to upload files to directories of other users, due to an insecure direct object reference. While the upload feature checks for user authentication, it fails to verify ownership of the directories where files are being uploaded.
This vulnerability could lead to unauthorized access to user files or directories, potentially allowing for the manipulation or deletion of user data.
Users can update to AVideo version 20.0 or later, where this vulnerability has been addressed.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.