Description
In AVideo through 29.0, the CloneSite plugin is vulnerable to stored OS command injection. In plugin/CloneSite/cloneClient.json.php (line ~270) the stored SSH password is substituted into the command string `sshpass -p '{password}' rsync ...` with a plain str_replace and no escaping, so a single quote in the password breaks out of the quoted word and injects arbitrary shell. The password is written through the admin-only endpoint objects/pluginAddDataObject.json.php, whose only CSRF defense (isUntrustedRequest()/forbidIfIsUntrustedRequest()) is a no-op when the request source appears to be loopback — as happens behind a same-host TLS-terminating reverse proxy with $global['trustedProxies'] unset — or when an attacker-controlled application is co-hosted on the same hostname; on HTTPS the session cookie is issued with SameSite=None, so a cross-site POST carries it. An unauthenticated remote attacker can therefore lure an authenticated administrator into planting a malicious password (and an attacker-controlled cloneSiteURL), after which the plugin's documented crontab entry executes the injected command with no further administrator action, as the crontab owner (commonly root or www-data). Exploitation requires the CloneSite plugin to be enabled with the documented crontab installed and one of the above CSRF channels; default single-process Apache deployments are reported as not CSRF-exploitable. This is a residual sink of CVE-2026-41304. The issue is confirmed at master HEAD (8963b6a1); no patched version is available.
Published: 2026-09-16
Score: 8.7 High
EPSS: 1.4% Low
KEV: No
Impact: Remote Code Execution via Stored Shell Injection
Action: Apply Workaround
AI Analysis

Impact

AVideo versions through 29.0 embed a stored OS command injection flaw in the CloneSite plugin. The plugin stores an SSH password that is later inserted unescaped into a shell command used by a scheduled cron task. When a single quote is added to that password, an attacker can terminate the quoted string and inject arbitrary shell commands, causing remote code execution on the host running the cron task. The vulnerability arises from a Trusted Proxy mis‑configuration and CSRF weaknesses that allow an unauthenticated attacker to trick an authenticated administrator into submitting a malicious password via the dedicated API. Once the malicious password is stored, the cron job runs automatically with privileges typically granted to root or www‑data, enabling the attacker to execute any command without further action.

Affected Systems

The issue affects installations of the AVideo platform by WWBN where the CloneSite plugin is enabled and the documented cron job is installed. This includes all versions up to and including 29.0. No specific affected product version list is supplied beyond the major version; any deployment that has the plugin enabled is considered vulnerable.

Risk and Exploitability

The flaw scores a CVSS of 8.7, indicating high severity, while the EPSS estimate of 1% suggests a low but non‑zero exploit probability at this time. It is not currently listed in the CISA KEV catalog. Exploitation requires that the CloneSite plugin be enabled, the cron job be present, and that CSRF filtering is bypassed via a trusted proxy or cross‑site request. The vulnerability permits arbitrary command execution with the privileges of the cron job owner, which is often high privileged, leading to full compromise of the underlying system. The risk is therefore significant for environments that rely on the CloneSite functionality and have not mitigated the CSRF and trusted‑proxy weaknesses.

Generated by OpenCVE AI on September 18, 2026 at 05:25 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Disable the CloneSite plugin to prevent the vulnerable configuration from being used.
  • Remove or comment out the crontab entry that executes the rsync command, ensuring that no scheduled task will run malicious commands.
  • Force proper trusted proxy configuration by setting the $global['trustedProxies'] variable, or remove loopback trust, to restore CSRF protection.

Generated by OpenCVE AI on September 18, 2026 at 05:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 02:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
Description In AVideo through 29.0, the CloneSite plugin is vulnerable to stored OS command injection. In plugin/CloneSite/cloneClient.json.php (line ~270) the stored SSH password is substituted into the command string `sshpass -p '{password}' rsync ...` with a plain str_replace and no escaping, so a single quote in the password breaks out of the quoted word and injects arbitrary shell. The password is written through the admin-only endpoint objects/pluginAddDataObject.json.php, whose only CSRF defense (isUntrustedRequest()/forbidIfIsUntrustedRequest()) is a no-op when the request source appears to be loopback — as happens behind a same-host TLS-terminating reverse proxy with $global['trustedProxies'] unset — or when an attacker-controlled application is co-hosted on the same hostname; on HTTPS the session cookie is issued with SameSite=None, so a cross-site POST carries it. An unauthenticated remote attacker can therefore lure an authenticated administrator into planting a malicious password (and an attacker-controlled cloneSiteURL), after which the plugin's documented crontab entry executes the injected command with no further administrator action, as the crontab owner (commonly root or www-data). Exploitation requires the CloneSite plugin to be enabled with the documented crontab installed and one of the above CSRF channels; default single-process Apache deployments are reported as not CSRF-exploitable. This is a residual sink of CVE-2026-41304. The issue is confirmed at master HEAD (8963b6a1); no patched version is available.
Title AVideo through 29.0 CloneSite Stored Shell Injection via SSH Password CSRF
First Time appeared Wwbn
Wwbn avideo
Weaknesses CWE-78
CPEs cpe:2.3:a:wwbn:avideo:*:*:*:*:*:*:*:*
Vendors & Products Wwbn
Wwbn avideo
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-19T02:01:45.439Z

Reserved: 2026-09-16T13:47:20.117Z

Link: CVE-2026-92580

cve-icon Vulnrichment

Updated: 2026-09-19T02:01:35.819Z

cve-icon NVD

Status : Deferred

Published: 2026-09-16T22:18:28.333

Modified: 2026-09-22T20:43:58.793

Link: CVE-2026-92580

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T19:00:06Z

Weaknesses
  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')