CVE-2025-34435

AVideo versions prior to 20.1 are vulnerable to an insecure direct object reference (IDOR) that allows any authenticated user to delete media files belonging to other users. The affected endpoint validates authentication but fails to verify ownership or edit permissions for the targeted video.
Configurations

Configuration 1 (hide)

cpe:2.3:a:wwbn:avideo:*:*:*:*:*:*:*:*

History

19 Dec 2025, 19:15

Type Values Removed Values Added
References
  • () https://chocapikk.com/posts/2025/avideo-security-vulnerabilities/ -

19 Dec 2025, 16:15

Type Values Removed Values Added
Summary (en) AVideo versions prior to 20.0 are vulnerable to an insecure direct object reference (IDOR) that allows any authenticated user to delete media files belonging to other users. The affected endpoint validates authentication but fails to verify ownership or edit permissions for the targeted video. (en) AVideo versions prior to 20.1 are vulnerable to an insecure direct object reference (IDOR) that allows any authenticated user to delete media files belonging to other users. The affected endpoint validates authentication but fails to verify ownership or edit permissions for the targeted video.

18 Dec 2025, 19:51

Type Values Removed Values Added
First Time Wwbn
Wwbn avideo
CPE cpe:2.3:a:wwbn:avideo:*:*:*:*:*:*:*:*
References () https://github.com/WWBN/AVideo/commit/275a54268b - () https://github.com/WWBN/AVideo/commit/275a54268b - Patch
References () https://github.com/WWBN/AVideo/commit/4a53ab2056 - () https://github.com/WWBN/AVideo/commit/4a53ab2056 - Patch
References () https://www.vulncheck.com/advisories/avideo-idor-arbitrary-file-deletion - () https://www.vulncheck.com/advisories/avideo-idor-arbitrary-file-deletion - Third Party Advisory
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.5

17 Dec 2025, 20:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-12-17 20:15

Updated : 2025-12-19 19:15


NVD link : CVE-2025-34435

Mitre link : CVE-2025-34435

CVE.ORG link : CVE-2025-34435


JSON object : View

Products Affected

wwbn

  • avideo
CWE
CWE-639

Authorization Bypass Through User-Controlled Key