CVE-2020-23489

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
16/11/2020
Last modified:
21/07/2021

Description

The import.json.php file before 8.9 for Avideo is vulnerable to a File Deletion vulnerability. This allows the deletion of configuration.php, which leads to certain privilege checks not being in place, and therefore a user can escalate privileges to admin.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:wwbn:avideo:*:*:*:*:*:*:*:* 8.9 (excluding)