Impact
AVideo versions through 29.0 embed a stored OS command injection flaw in the CloneSite plugin. The plugin stores an SSH password that is later inserted unescaped into a shell command used by a scheduled cron task. When a single quote is added to that password, an attacker can terminate the quoted string and inject arbitrary shell commands, causing remote code execution on the host running the cron task. The vulnerability arises from a Trusted Proxy mis‑configuration and CSRF weaknesses that allow an unauthenticated attacker to trick an authenticated administrator into submitting a malicious password via the dedicated API. Once the malicious password is stored, the cron job runs automatically with privileges typically granted to root or www‑data, enabling the attacker to execute any command without further action.
Affected Systems
The issue affects installations of the AVideo platform by WWBN where the CloneSite plugin is enabled and the documented cron job is installed. This includes all versions up to and including 29.0. No specific affected product version list is supplied beyond the major version; any deployment that has the plugin enabled is considered vulnerable.
Risk and Exploitability
The flaw scores a CVSS of 8.7, indicating high severity, while the EPSS estimate of 1% suggests a low but non‑zero exploit probability at this time. It is not currently listed in the CISA KEV catalog. Exploitation requires that the CloneSite plugin be enabled, the cron job be present, and that CSRF filtering is bypassed via a trusted proxy or cross‑site request. The vulnerability permits arbitrary command execution with the privileges of the cron job owner, which is often high privileged, leading to full compromise of the underlying system. The risk is therefore significant for environments that rely on the CloneSite functionality and have not mitigated the CSRF and trusted‑proxy weaknesses.
OpenCVE Enrichment