← back
CVE-2022-30547criticalCWE-22

CVE-2022-30547

40Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 9.9epss 64%
exploitation probability
64%top 1% of all CVEs
observed exploitation
nono source reports it
In short

A flaw in AVideo's file extraction feature allows attackers to escape the intended directory and execute arbitrary commands on the server by sending a specially-crafted request. This is a critical vulnerability that gives attackers full control over the system.

Technical detail

A directory traversal vulnerability in the unzipDirectory function (CWE-22) allows unauthenticated remote attackers to traverse outside the intended extraction directory and achieve arbitrary command execution. The vulnerability is triggered via malicious HTTP requests and affects AVideo 11.6 and the dev master branch.

Summary generated and translated by AI from the official description.
A directory traversal vulnerability exists in the unzipDirectory functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. A specially-crafted HTTP request can lead to arbitrary command execution. An attacker can send an HTTP request to trigger this vulnerability.
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Affected products
WWBN · AVideo