WWBN AVideo
cpe:2.3:a:wwbn:avideo:*:*:*:*:*:*:*
- < 20.0
A vulnerability exists in AVideo versions prior to 20.0, allowing users with upload permissions to arbitrarily modify the rotation metadata of any video. This insecure direct object reference (IDOR) vulnerability arises because the endpoint checks for upload rights but does not verify ownership or management privileges for the video being edited.
Exploitation of this vulnerability allows for unauthorized modification of video rotation metadata, which could disrupt the intended presentation or usage of the video.
Users can upgrade to AVideo version 20.0 or later, where this vulnerability has been addressed.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.