AVideo versions prior to 20.0 are vulnerable to an insecure direct object reference (IDOR) that allows any authenticated user to delete media files belonging to other users. The affected endpoint validates authentication but fails to verify ownership or edit permissions for the targeted video.
History

Wed, 17 Dec 2025 21:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 17 Dec 2025 20:00:00 +0000

Type Values Removed Values Added
Description AVideo versions prior to 20.0 are vulnerable to an insecure direct object reference (IDOR) that allows any authenticated user to delete media files belonging to other users. The affected endpoint validates authentication but fails to verify ownership or edit permissions for the targeted video.
Title AVideo < 20.0 IDOR Arbitrary File Deletion
Weaknesses CWE-639
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2025-12-17T20:30:00.458Z

Reserved: 2025-04-15T19:15:22.601Z

Link: CVE-2025-34435

cve-icon Vulnrichment

Updated: 2025-12-17T20:24:16.827Z

cve-icon NVD

Status : Received

Published: 2025-12-17T20:15:53.883

Modified: 2025-12-17T20:15:53.883

Link: CVE-2025-34435

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.