GHSA-wqcc-qf63-c2x4
GitHub Security Advisory
WWBN AVideo Insufficient Entropy vulnerbaility
✓ GitHub Reviewed
CRITICAL
Has CVE
Advisory Details
An insufficient entropy vulnerability exists in the salt generation functionality of WWBN AVideo dev master commit 15fed957fb. A specially crafted series of HTTP requests can lead to privilege escalation. An attacker can gather system information via HTTP requests and bruteforce the salt offline, leading to forging a legitimate password recovery code for the admin user.
Affected Packages
Packagist
wwbn/avideo
Affected versions:
0
(last affected: 12.4)
Related CVEs
Key Information
9.0
/10
Dataset
Last updated: November 26, 2025 6:30 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.