CVE-2025-34435

AVideo versions prior to 20.1 are vulnerable to an insecure direct object reference (IDOR) that allows any authenticated user to delete media files belonging to other users. The affected endpoint validates authentication but fails to verify ownership or edit permissions for the targeted video.
Configurations

Configuration 1 (hide)

cpe:2.3:a:wwbn:avideo:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2025-12-17 20:15

Updated : 2025-12-19 19:15


NVD link : CVE-2025-34435

Mitre link : CVE-2025-34435

CVE.ORG link : CVE-2025-34435


JSON object : View

Products Affected

wwbn

  • avideo
CWE
CWE-639

Authorization Bypass Through User-Controlled Key