AVideo is an open source video platform. Prior to version 12.4, an OS Command Injection vulnerability in an authenticated endpoint `/plugin/CloneSite/cloneClient.json.php` allows attackers to achieve Remote Code Execution. This issue is fixed in version 12.4.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| wwbn/avideo(Packagist) | 0 | 12.4 | N/A |
CVSS Metrics