An arbitrary file overwrite vulnerability in RAREPROB SOLUTIONS PRIVATE LIMITED Video player Play All Videos v1.0.135 allows attackers to overwrite critical internal files via the file import process, leading to arbtrary code execution or information exposure.
References
| Link | Resource |
|---|---|
| https://github.com/Secsys-FDU/AF_CVEs/issues/29 | Exploit Third Party Advisory Issue Tracking |
| https://rareprob-website.firebaseapp.com/ | Product |
| https://secsys.fudan.edu.cn/ | Not Applicable |
Configurations
History
02 Apr 2026, 20:44
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Rareprob video Player
Rareprob |
|
| CPE | cpe:2.3:a:rareprob:video_player:1.0.135:*:*:*:*:android:*:* | |
| References | () https://github.com/Secsys-FDU/AF_CVEs/issues/29 - Exploit, Third Party Advisory, Issue Tracking | |
| References | () https://rareprob-website.firebaseapp.com/ - Product | |
| References | () https://secsys.fudan.edu.cn/ - Not Applicable |
01 Apr 2026, 16:23
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 5.3 |
| CWE | CWE-434 |
31 Mar 2026, 20:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-03-31 20:16
Updated : 2026-04-02 20:44
NVD link : CVE-2026-30280
Mitre link : CVE-2026-30280
CVE.ORG link : CVE-2026-30280
JSON object : View
Products Affected
rareprob
- video_player
CWE
CWE-434
Unrestricted Upload of File with Dangerous Type
