8.7
/ 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N
Description
WWBN AVideo is an open source video platform. In versions 29.0 and prior, the locale save endpoint (`locale/save.php`) constructs a file path by directly concatenating `$_POST['flag']` into the path at line 30 without any sanitization. The `$_POST['code']` parameter is then written verbatim to that path via `fwrite()` at line 40. An admin attacker (or any user who can CSRF an admin, since no CSRF token is checked and cookies use `SameSite=None`) can traverse out of the `locale/` directory and write arbitrary `.php` files to any writable location on the filesystem, achieving Remote Code Execution. Commit 57f89ffbc27d37c9d9dd727212334846e78ac21a fixes the issue.
AI Analysis
Path Traversal vulnerability in WWBN AVideo locale save endpoint, allowing arbitrary PHP file write to any web-accessible directory, resulting in Remote Code Execution
Basic Information
ID
CVE-2026-40909
Source
GitHub_M
Published
Apr 21, 2026 at 19:54
Modified
Apr 21, 2026 at 20:36
Affected Product
Vendor
WWBN
Product
AVideo
Version
<= 29.0
Affected Versions
WWBN AVideo <= 29.0
CWE Classification
AI Assessment
AI Score
8.7 / 10
AI Severity
High
Vendor
WWBN
Product
AVideo
Version
<= 29.0