AVideo versions prior to 20.0 with the ImageGallery plugin enabled is vulnerable to unauthenticated file upload and deletion. Plugin endpoints responsible for managing gallery images fail to enforce authentication checks and do not validate ownership, allowing unauthenticated attackers to upload or delete images associated with any image-based video.
Metrics
Affected Vendors & Products
References
History
Wed, 17 Dec 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 17 Dec 2025 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | AVideo versions prior to 20.0 with the ImageGallery plugin enabled is vulnerable to unauthenticated file upload and deletion. Plugin endpoints responsible for managing gallery images fail to enforce authentication checks and do not validate ownership, allowing unauthenticated attackers to upload or delete images associated with any image-based video. | |
| Title | AVideo < 20.0 ImageGallery Plugin Unauthenticated File Upload and Deletion | |
| Weaknesses | CWE-306 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2025-12-17T20:30:19.549Z
Reserved: 2025-04-15T19:15:22.601Z
Link: CVE-2025-34434
Updated: 2025-12-17T20:25:03.811Z
Status : Received
Published: 2025-12-17T20:15:53.740
Modified: 2025-12-17T20:15:53.740
Link: CVE-2025-34434
No data.
OpenCVE Enrichment
No data.