Loading...
Skip to main content

CVE-2023-49599

CRITICAL

WWBN AVideo Insufficient Entropy vulnerbaility

Published January 10, 2024Updated November 4, 2025Source: osv

Summary

An insufficient entropy vulnerability exists in the salt generation functionality of WWBN AVideo dev master commit 15fed957fb. A specially crafted series of HTTP requests can lead to privilege escalation. An attacker can gather system information via HTTP requests and bruteforce the salt offline, leading to forging a legitimate password recovery code for the admin user.

Affected Packages (1)

PackageEcosystemAffectedFixed In
wwbn/avideo
packagist
10.4, 10.8, 11, 11.1 (+4 more)Range-based data available

Vulnerability Classification

Common Weakness Enumeration (CWE) identifiers for this vulnerability type.

CVSS Score Breakdown

What the CVSS (Common Vulnerability Scoring System) 9.8 score means for each attack dimension.

Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Frequently Asked Questions

What is CVE-2023-49599?
WWBN AVideo Insufficient Entropy vulnerbaility This vulnerability has been assigned a severity rating of CRITICAL (CVSS score: 9.8/10).
How do I check if my project is affected by CVE-2023-49599?
CVE-2023-49599 affects wwbn/avideo. Use GeekWala's free vulnerability scanner to check your dependencies against CVE-2023-49599 and 200,000+ other known vulnerabilities.

Severity & Exploitability

CVSS Score
9.8

Exploitation is straightforward and causes maximum impact. Patch immediately.

Also Known As

GHSA-wqcc-qf63-c2x4

Related CVEs

  • CVE-2026-33352
    CRITICAL

    AVideo has an Unauthenticated SQL Injection via `doNotShowCats` Parameter (Backslash Escape Bypass)

  • CVE-2023-25313
    CRITICAL

    AVideo contains Command injection when embedding a video link

  • CVE-2026-28501
    CRITICAL

    AVideo has Unauthenticated SQL Injection via JSON Request Bypass in objects/videos.json.php

  • CVE-2026-28502
    CRITICAL

    AVideo has Authenticated Remote Code Execution via Unsafe Plugin ZIP Extraction

  • CVE-2026-33480
    HIGH

    AVideo has a SSRF Protection Bypass via IPv4-Mapped IPv6 Addresses in Unauthenticated LiveLinks Proxy

  • CVE-2026-41064
    HIGH

    WWBN AVideo has an incomplete fix for CVE-2026-33502: Command Injection

  • CVE-2026-33719
    HIGH

    AVideo: Unauthenticated CDN Configuration Takeover via Empty Default Key Bypass and Mass-Assignment

  • CVE-2026-40925
    HIGH

    WWBN AVideo has CSRF in configurationUpdate.json.php Enables Full Site Configuration Takeover Including Encoder URL and SMTP Credentials

Check if you're affected

Scan your dependencies to see if this vulnerability affects your projects.

Scan Your Dependencies