Loading HuntDB...

GHSA-wqcc-qf63-c2x4

GitHub Security Advisory

WWBN AVideo Insufficient Entropy vulnerbaility

✓ GitHub Reviewed CRITICAL Has CVE

Advisory Details

An insufficient entropy vulnerability exists in the salt generation functionality of WWBN AVideo dev master commit 15fed957fb. A specially crafted series of HTTP requests can lead to privilege escalation. An attacker can gather system information via HTTP requests and bruteforce the salt offline, leading to forging a legitimate password recovery code for the admin user.

Affected Packages

Packagist wwbn/avideo
Affected versions: 0 (last affected: 12.4)

Related CVEs

Key Information

GHSA ID
GHSA-wqcc-qf63-c2x4
Published
January 10, 2024 6:30 PM
Last Modified
November 4, 2025 10:11 PM
CVSS Score
9.0 /10
Primary Ecosystem
Packagist
Primary Package
wwbn/avideo
GitHub Reviewed
✓ Yes

Dataset

Last updated: November 26, 2025 6:30 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.