Dismissed
(no matching packages found)
Activity log
- Created & dismissed (no matching packages found) suggestion
All-in-One Video Gallery < 4.9.2 - Subscriber+ Server-Side Request Forgery via 'vdl' Parameter
All-in-One Video Gallery registers a public, unauthenticated file-download handler triggered by `?vdl=<post_id>` on any `aiovg_videos` post (`public/video.php`, `AIOVG_Public_Video::download_video()`), which reads the post's `mp4` meta value and streams that URL's response back to the requester.
References
-
https://wpscan.com/vulnerability/ad70162f-5514-41b8-84af-c79c2f881567/ technical-descriptionvdb-entryexploit
Affected products
All-in-One Video Gallery
- <4.9.2