Back to Database
Status published
High
CVE-2023-30854
WWBN AVideo vulnerable to OS Command Injection
Vulnerability Description
AVideo is an open source video platform. Prior to version 12.4, an OS Command Injection vulnerability in an authenticated endpoint `/plugin/CloneSite/cloneClient.json.php` allows attackers to achieve Remote Code Execution. This issue is fixed in version 12.4.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2023-30854
Credits & Attribution
No credits recorded in the NVD database.
More from WWBN
View All →CVE-2025-53084
A cross-site scripting (xss) vulnerability exists in the videosList page...
Critical
9
CVE-2025-50128
A cross-site scripting (xss) vulnerability exists in the videoNotFound 404ErrorMsg...
Critical
9.6
CVE-2025-48732
An incomplete blacklist exists in the .htaccess sample of WWBN...
High
7.3
CVE-2025-46410
A cross-site scripting (xss) vulnerability exists in the managerPlaylists PlaylistOwnerUsersId...
Critical
9.6
CVE-2025-41420
A cross-site scripting (xss) vulnerability exists in the userLogin cancelUri...
Critical
9.6
Affected Vendor
WWBN
View all reports →Affected Software
AVideo
Vulnerable Versions:
< 12.4
Timeline
Official Publish:
April 28th, 2023
Last Modified:
January 30th, 2025
Added to House:
July 22nd, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H