CVE-2023-30854: Wwbn Avideo

High severity, CVSS 8.8. EPSS: 5.2% chance of exploitation in the next 30 days.

AVideo is an open source video platform. Prior to version 12.4, an OS Command Injection vulnerability in an authenticated endpoint `/plugin/CloneSite/cloneClient.json.php` allows attackers to achieve Remote Code Execution. This issue is fixed in version 12.4.

Affected products

  • Wwbn Avideo: before 12.4 (fixed in 12.4)

Published 2023-04-28. Last modified 2026-06-17.