AVideo/YouPHPTube 10.0 and prior is affected by Insecure file write. An administrator privileged user is able to write files on filesystem using flag and code variables in file save.php.
References
Link | Resource |
---|---|
http://avideoyouphptube.com | Broken Link Product URL Repurposed |
https://synacktiv.com | Product |
https://www.synacktiv.com/sites/default/files/2021-01/YouPHPTube_Multiple_Vulnerabilities.pdf | Exploit Vendor Advisory |
Configurations
History
No history.
Information
Published : 2021-11-01 12:15
Updated : 2024-02-14 01:17
NVD link : CVE-2021-25877
Mitre link : CVE-2021-25877
CVE.ORG link : CVE-2021-25877
JSON object : View
Products Affected
youphptube
- youphptube
CWE
CWE-94
Improper Control of Generation of Code ('Code Injection')