AVideo is an open source video platform. Prior to version 12.4, an OS Command Injection vulnerability in an authenticated endpoint `/plugin/CloneSite/cloneClient.json.php` allows attackers to achieve Remote Code Execution. This issue is fixed in version 12.4.
No PoCs from references.
- https://github.com/ARPSyndicate/cve-scores
- https://github.com/jmrcsnchz/CVE-2023-30854
- https://github.com/jmrcsnchz/CVE-2023-32073
- https://github.com/nomi-sec/PoC-in-GitHub