Authorization Bypass in AVideo's Meet Plugin Affects User Sessions
⚠️ CVE-Referenzen:
CVE-2026-56345
Avideo - Avideo - CRITICAL - CVE-2026-56345.
AVideo's Meet plugin, up to version 29.0, suffers from an authorization bypass vulnerability that allows attackers to exploit the uploadRecordedVideo.json.php endpoint. By manipulating the filename of a malicious file upload, an adversary can derive a target user's ID and invoke a passwordless login, defeating normal authentication measures. Knowledge of the Meet shared secret, which could be compromised through path traversal vulnerabilities or timing attacks, enables the attacker to craft a file that triggers an authenticated session as any user, including administrators. This flaw poses a serious risk of account takeover, allowing potential full control over user sessions.
Quelle: securityvulnerability.io