Vulnerabilities > CVE-2020-23489 - Missing Authorization vulnerability in Wwbn Avideo
Attack vector
NETWORK Attack complexity
LOW Privileges required
LOW Confidentiality impact
HIGH Integrity impact
HIGH Availability impact
HIGH Summary
The import.json.php file before 8.9 for Avideo is vulnerable to a File Deletion vulnerability. This allows the deletion of configuration.php, which leads to certain privilege checks not being in place, and therefore a user can escalate privileges to admin.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | Wwbn
| 22 |