CVE-2023-49599
WWBN AVideo Insufficient Entropy vulnerbaility
Summary
Affected Packages (1)
| Package | Ecosystem | Affected | Fixed In |
|---|---|---|---|
| wwbn/avideo | packagist | 10.4, 10.8, 11, 11.1 (+4 more) | Range-based data available |
Vulnerability Classification
Common Weakness Enumeration (CWE) identifiers for this vulnerability type.
- CWE-331
CVSS Score Breakdown
What the CVSS (Common Vulnerability Scoring System) 9.8 score means for each attack dimension.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
References
Frequently Asked Questions
- What is CVE-2023-49599?
- WWBN AVideo Insufficient Entropy vulnerbaility This vulnerability has been assigned a severity rating of CRITICAL (CVSS score: 9.8/10).
- How do I check if my project is affected by CVE-2023-49599?
- CVE-2023-49599 affects wwbn/avideo. Use GeekWala's free vulnerability scanner to check your dependencies against CVE-2023-49599 and 200,000+ other known vulnerabilities.
Severity & Exploitability
Exploitation is straightforward and causes maximum impact. Patch immediately.
Also Known As
Related CVEs
- CVE-2026-33352CRITICAL
AVideo has an Unauthenticated SQL Injection via `doNotShowCats` Parameter (Backslash Escape Bypass)
- CVE-2023-25313CRITICAL
AVideo contains Command injection when embedding a video link
- CVE-2026-28501CRITICAL
AVideo has Unauthenticated SQL Injection via JSON Request Bypass in objects/videos.json.php
- CVE-2026-28502CRITICAL
AVideo has Authenticated Remote Code Execution via Unsafe Plugin ZIP Extraction
- CVE-2026-33480HIGH
AVideo has a SSRF Protection Bypass via IPv4-Mapped IPv6 Addresses in Unauthenticated LiveLinks Proxy
- CVE-2026-41064HIGH
WWBN AVideo has an incomplete fix for CVE-2026-33502: Command Injection
- CVE-2026-33719HIGH
AVideo: Unauthenticated CDN Configuration Takeover via Empty Default Key Bypass and Mass-Assignment
- CVE-2026-40925HIGH
WWBN AVideo has CSRF in configurationUpdate.json.php Enables Full Site Configuration Takeover Including Encoder URL and SMTP Credentials
Check if you're affected
Scan your dependencies to see if this vulnerability affects your projects.
Scan Your Dependencies