{"id":"GHSA-3mjv-375j-6h92","summary":"AVideo: Authenticated Arbitrary File Read in view/update.php","details":"### Summary\nview/update.php reads $_POST['updateFile'] as a relative path under updatedb/ and passes it to PHP's file() for line-by-line execution as part of a database migration. An authenticated administrator can abuse this to read arbitrary text files reachable from the web-server process — especially valuable on misconfigured deployments where /etc/passwd, .env, or other sibling-app configs are reachable relative to the AVideo directory.\n\n### Details\nview/update.php, lines 134-145 (excerpt):\n\nif (!empty($_POST['updateFile'])) {\n    $dir = Video::getStoragePath() . \"cache\";\n    rrmdir($dir);\n    /* …unrelated cache-clear… */\n\n    if (file_exists($logfile . \"log\")) {\n        unlink($logfile . \"log\");\n        // ...\n    }\n    $lines = file(\"{$global['systemRootPath']}updatedb/{$_POST['updateFile']}\");\nThe User::isAdmin() and adminSecurityCheck(true) guards at lines 12-15 enforce admin auth, but $_POST['updateFile'] is concatenated into a path without any sanitization. file() returns the file's contents as an array of lines; the script subsequently iterates them and echoes the SQL it would run.\n\n### PoC\nPOST /view/update.php\nContent-Type: application/x-www-form-urlencoded\n\nupdateFile=../../../../etc/passwd\nResult: the script attempts to load /etc/passwd (relative to {systemRootPath}updatedb/), echoing each line in the migration-runner HTML output. $_POST['updateFile'] traversal accepted, no extension guard, no in-array whitelist.\n\nAttempting ../../../../proc/self/environ similarly reveals web-server environment variables on Linux.\n\n\n\n### Impact\nVerified on the current master branch of WWBN/AVideo (commit bc0340662…). Likely affected: every release where view/update.php contains the $_POST['updateFile'] consumer — pattern predates 2024.","aliases":["CVE-2026-45731"],"modified":"2026-09-10T03:51:04.396226571Z","published":"2026-05-18T19:01:59Z","database_specific":{"github_reviewed_at":"2026-05-18T19:01:59Z","nvd_published_at":"2026-05-29T14:16:31Z","cwe_ids":["CWE-22"],"severity":"MODERATE","github_reviewed":true},"references":[{"type":"WEB","url":"https://github.com/WWBN/AVideo/security/advisories/GHSA-3mjv-375j-6h92"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-45731"},{"type":"PACKAGE","url":"https://github.com/WWBN/AVideo"}],"affected":[{"package":{"name":"WWBN/AVideo","ecosystem":"Packagist","purl":"pkg:composer/WWBN/AVideo"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"29.0"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/05/GHSA-3mjv-375j-6h92/GHSA-3mjv-375j-6h92.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N"}]}