Daniel Neto
127 exploits
Active since May 2023
AVideo Encoder downloadURL SSRF via unpinned retry fallback
CVSS 6.4
AVideo Has Unauthenticated .env File Exposure via Official Docker Compose Configuration
CVSS 7.5
AVideo has an Authorize.Net Webhook Signature Bypass that Enables Wallet Balance Inflation via Forged Payment Data
CVSS 6.5
AVideo < 29.0 - Command Injection
CVSS 8.1
WWBN AVideo <= 29.0 MessageSQLite - Stored Cross-Site Scripting
AVideo Has Unauthenticated Reflected XSS via $_GET['search'] in YouTubeAPI Gallery Pagination
CVSS 6.1
WWBN AVideo: Stored XSS via Hostile YouTube Video Title in AVideo YouTubeAPI Gallery Section
CVSS 4.7
AVideo: Unauthenticated Stored DOM Cross-Site Scripting via Per-Client Metadata Broadcast in YPTSocket Plugin
CVSS 9.6
AVideo - Stored Cross-Site Scripting via Unescaped User-Agent in Participants Panel
CVSS 6.1
WWBN AVideo: Unauthenticated Disclosure of CloneSite `myKey` via Error Echo in `cloneClient.json.php` Enables Cross-Site DB Dump of the Configured Clone Server
CVSS 7.5
WWBN AVideo: Incomplete Fix for YPTSocket autoEvalCodeOnHTML Strip: Unauthenticated Cross-User JavaScript Execution via `$msg['json']` Relay Bypass
CVSS 7.2
WWBN AVideo: Password Hash Leaked in MobileManager OAuth Redirect URL Enables Account Takeover
CVSS 6.8
WWBN AVideo: HTML Injection in notifySubscribers.json.php Enables Platform-Branded Phishing Emails to Channel Subscribers
CVSS 6.4
WWBN AVideo: CSRF in userSavePhoto.php Allows Cross-Origin Overwrite of Any Logged-in User's Profile Photo with Arbitrary Bytes
CVSS 5.4
WWBN AVideo: Reflected XSS in plugin/Meet/iframe.php via Unescaped `user`/`pass` Parameters Reflected into JavaScript String Literal
CVSS 6.1
WWBN AVideo: Blind SSRF in YPTWallet Donation Webhook via Missing isSSRFSafeURL() Check and CURLOPT_FOLLOWLOCATION Redirect Bypass
CVSS 5.4
WWBN AVideo: Unauthenticated Arbitrary Email Sending via sendEmail.json.php Allows Phishing from Site's Legitimate From Address
CVSS 5.3
WWBN AVideo <= 29.0 - Unauthenticated User Enumeration
CVSS 5.3
WWBN AVideo: Unauthenticated CRLF/ICS Injection in Scheduler downloadICS.php Allows Calendar Event Spoofing
CVSS 4.3
WWBN AVideo: IDOR in PayPalYPT agreementCancel.json.php Allows Any Authenticated User to Cancel Arbitrary PayPal Subscription Agreements
CVSS 4.2
WWBN AVideo: SSRF Protection Bypass via HTTP Redirect and DNS Rebinding in isSSRFSafeURL()
CVSS 7.7
WWBN AVideo: Exposure of Sensitive Information to an Unauthorized Actor and Missing Authorization
WWBN AVideo < 12.4 - Remote Code Execution via CloneSite Plugin
CVSS 8.8
AVideo has Unauthenticated Information Disclosure of User Group Permission Mappings via Permissions Plugin
CVSS 5.3
WWBN AVideo LiveLinks Proxy - Server-Side Request Forgery
CVSS 8.6