CVE-2025-34436
Unknown Unknown - Not Provided
BaseFortify

Publication date: 2025-12-17

Last updated on: 2025-12-19

Assigner: VulnCheck

Description
AVideo versions prior to 20.1 allow any authenticated user to upload files into directories belonging to other users due to an insecure direct object reference. The upload functionality verifies authentication but does not enforce ownership checks.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2025-12-17
Last Modified
2025-12-19
Generated
2026-05-07
AI Q&A
2025-12-17
EPSS Evaluated
2026-05-05
NVD
Affected Vendors & Products
Showing 1 associated CPE
Vendor Product Version / Range
wwbn avideo to 20.0 (exc)
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-639 The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?

CVE-2025-34436 is an Insecure Direct Object Reference (IDOR) vulnerability in AVideo versions prior to 20.0. It allows any authenticated user to upload arbitrary files into directories belonging to other users because the upload functionality checks only if the user is authenticated but does not verify if the user owns or is authorized to upload to the target directory. [1]


How can this vulnerability impact me? :

This vulnerability can lead to unauthorized file uploads into other users' directories, potentially compromising confidentiality, integrity, and availability of data. An attacker with low privileges can exploit this flaw remotely without user interaction, which may result in data breaches, malware uploads, or disruption of service. [1]


How can this vulnerability be detected on my network or system? Can you suggest some commands?

To detect this vulnerability, you can check if your AVideo installation is running a version prior to 20.0, as these versions are affected. Additionally, monitoring file upload activities for unauthorized uploads into other users' directories may help identify exploitation attempts. Specific commands are not provided in the available resources. [1]


What immediate steps should I take to mitigate this vulnerability?

The immediate mitigation step is to upgrade AVideo to version 20.0 or later, where this vulnerability has been fixed. Until the upgrade, restrict authenticated users' permissions to prevent uploading files into directories they do not own. [1]


Ask Our AI Assistant
Need more information? Ask your question to get an AI reply (Powered by our expertise)
0/70
EPSS Chart