{"id":"CVE-2026-45731","aliases":["GHSA-3mjv-375j-6h92"],"url":"https://o3.security/vulnerability/CVE-2026-45731","summary":"WWBN AVideo: Authenticated Arbitrary File Read in view/update.php","details":"### Summary\nview/update.php reads $_POST['updateFile'] as a relative path under updatedb/ and passes it to PHP's file() for line-by-line execution as part of a database migration. An authenticated administrator can abuse this to read arbitrary text files reachable from the web-server process — especially valuable on misconfigured deployments where /etc/passwd, .env, or other sibling-app configs are reachable relative to the AVideo directory.\n\n### Details\nview/update.php, lines 134-145 (excerpt):\n\nif (!empty($_POST['updateFile'])) {\n    $dir = Video::getStoragePath() . \"cache\";\n    rrmdir($dir);\n    /* …unrelated cache-clear… */\n\n    if (file_exists($logfile . \"log\")) {\n        unlink($logfile . \"log\");\n        // ...\n    }\n    $lines = file(\"{$global['systemRootPath']}updatedb/{$_POST['updateFile']}\");\nThe User::isAdmin() and adminSecurityCheck(true) guards at lines 12-15 enforce admin auth, but $_POST['updateFile'] is concatenated into a path without any sanitization. file() returns the file's contents as an array of lines; the script subsequently iterates them and echoes the SQL it would run.\n\n### PoC\nPOST /view/update.php\nContent-Type: application/x-www-form-urlencoded\n\nupdateFile=../../../../etc/passwd\nResult: the script attempts to load /etc/passwd (relative to {systemRootPath}updatedb/), echoing each line in the migration-runner HTML output. $_POST['updateFile'] traversal accepted, no extension guard, no in-array whitelist.\n\nAttempting ../../../../proc/self/environ similarly reveals web-server environment variables on Linux.\n\n\n\n### Impact\nVerified on the current master branch of WWBN/AVideo (commit bc0340662…). Likely affected: every release where view/update.php contains the $_POST['updateFile'] consumer — pattern predates 2024.","published":"2026-05-29T13:05:02.855Z","modified":"2026-08-12T03:51:18.377001311Z","cvss":null,"epss":{"score":0.00469,"percentile":0.39619,"asOf":"2026-09-17"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"WWBN/AVideo","fixedVersion":null}],"fix":null,"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/45xxx/CVE-2026-45731.json"},{"type":"ADVISORY","url":"https://github.com/WWBN/AVideo/security/advisories/GHSA-3mjv-375j-6h92"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-45731"},{"type":"PACKAGE","url":"https://github.com/WWBN/AVideo"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:18.377001311Z"}}