CVE-2023-32073
HIGHWWBN AVideo < 12.4 - Remote Code Execution via CloneSite Plugin
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2023-32073. PoCs published by jmrcsnchz.
AI-analyzed exploit summary This PoC demonstrates an authenticated RCE vulnerability in WWBN AVideo via command injection in the CloneSite plugin. The exploit bypasses the fix for CVE-2023-30854 by leveraging unsanitized input in the `cloneSiteURL` parameter.
Description
WWBN AVideo is an open source video platform. In versions 12.4 and prior, a command injection vulnerability exists at `plugin/CloneSite/cloneClient.json.php` which allows Remote Code Execution if you CloneSite Plugin. This is a bypass to the fix for CVE-2023-30854, which affects WWBN AVideo up to version 12.3. This issue is patched in commit 1df4af01f80d56ff2c4c43b89d0bac151e7fb6e3.
Exploits (1)
This PoC demonstrates an authenticated RCE vulnerability in WWBN AVideo via command injection in the CloneSite plugin. The exploit bypasses the fix for CVE-2023-30854 by leveraging unsanitized input in the `cloneSiteURL` parameter.
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H