Metrics
Affected Vendors & Products
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Wed, 17 Dec 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 17 Dec 2025 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | AVideo versions prior to 20.0 with the ImageGallery plugin enabled is vulnerable to unauthenticated file upload and deletion. Plugin endpoints responsible for managing gallery images fail to enforce authentication checks and do not validate ownership, allowing unauthenticated attackers to upload or delete images associated with any image-based video. | |
| Title | AVideo < 20.0 ImageGallery Plugin Unauthenticated File Upload and Deletion | |
| Weaknesses | CWE-306 | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2025-12-17T20:30:19.549Z
Reserved: 2025-04-15T19:15:22.601Z
Link: CVE-2025-34434
Updated: 2025-12-17T20:25:03.811Z
Status : Received
Published: 2025-12-17T20:15:53.740
Modified: 2025-12-17T20:15:53.740
Link: CVE-2025-34434
No data.
OpenCVE Enrichment
No data.