AVideo Platform is an open-source Audio and Video platform. It is similar to a self-hosted YouTube. In AVideo Platform before version 10.2 there is an authorization bypass vulnerability which enables an ordinary user to get admin control. This is fixed in version 10.2. All queries now remove the pass hash and the recoverPass hash.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2021-02-01T15:25:19

Updated: 2024-08-03T18:09:15.033Z

Reserved: 2020-12-22T00:00:00

Link: CVE-2021-21286

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2021-02-01T16:15:13.047

Modified: 2021-02-05T18:33:56.493

Link: CVE-2021-21286

cve-icon Redhat

No data.