CVE-2026-45731

WWBN AVideo is an open source video platform. In 29.0 and earlier, view/update.php reads $_POST['updateFile'] as a relative path under updatedb/ and passes it to PHP's file() for line-by-line execution as part of a database migration. An authenticated administrator can abuse this to read arbitrary text files reachable from the web-server process.
Configurations

Configuration 1 (hide)

cpe:2.3:a:wwbn:avideo:*:*:*:*:*:*:*:*

History

21 Jul 2026, 12:10

Type Values Removed Values Added
Summary
  • (es) WWBN AVideo es una plataforma de video de código abierto. En la versión 29.0 y anteriores, view/update.php lee $_POST['updateFile'] como una ruta relativa bajo updatedb/ y lo pasa a la función file() de PHP para su ejecución línea por línea como parte de una migración de base de datos. Un administrador autenticado puede abusar de esto para leer archivos de texto arbitrarios accesibles desde el proceso del servidor web.

01 Jun 2026, 18:39

Type Values Removed Values Added
References () https://github.com/WWBN/AVideo/security/advisories/GHSA-3mjv-375j-6h92 - () https://github.com/WWBN/AVideo/security/advisories/GHSA-3mjv-375j-6h92 - Exploit, Vendor Advisory
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 4.9
First Time Wwbn
Wwbn avideo
CPE cpe:2.3:a:wwbn:avideo:*:*:*:*:*:*:*:*

29 May 2026, 15:16

Type Values Removed Values Added
References () https://github.com/WWBN/AVideo/security/advisories/GHSA-3mjv-375j-6h92 - () https://github.com/WWBN/AVideo/security/advisories/GHSA-3mjv-375j-6h92 -

29 May 2026, 14:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-29 14:16

Updated : 2026-07-21 12:10


NVD link : CVE-2026-45731

Mitre link : CVE-2026-45731

CVE.ORG link : CVE-2026-45731


JSON object : View

Products Affected

wwbn

  • avideo
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')