AVideo through commit c3edcc274c contains an authorization bypass vulnerability where a session cookie named 'key' with value 'value' overrides the $_REQUEST['key'] parameter in saveLive.php and rela…
High CVSS 7.5
Summary
AVideo through commit c3edcc274c contains an authorization bypass vulnerability where a session cookie named 'key' with value 'value' overrides the $_REQUEST['key'] parameter in saveLive.php and related endpoints. Attackers can publish to any user's RTMP stream without authentication by using the known constant stream key value to hijack live broadcasts.
In-depth triage
No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).
Sources
- NVD DATABASE
Original Links
- https://github.com/WWBN/AVideo/security/advisories/GHSA-5664-h9h4-3gwc
- https://www.vulncheck.com/advisories/avideo-through-c3edcc274c-authorization-bypass-via-session-cookie
Timeline
- nvd_ingest NVD