Vulnerabilidad · Publicado 01/09/2026
AVideo presenta una vulnerabilidad alta (CVSS 8.2) en el módulo de transmisión en vivo que permite a atacantes no autenticados modificar el estado de transmisiones programadas mediante solicitudes POST manipuladas. Esta vulnerabilidad afecta principalmente a plataformas de streaming y educativas en LATAM que utilizan este software de código abierto. Los atacantes pueden deshabilitar o sabotear retransmisiones sin acceso previo al sistema.
AVideo contains a missing authentication vulnerability in plugin/Live/on_publish.php that allows unauthenticated attackers to mark arbitrary scheduled broadcasts as failed by sending crafted POST requests with schedule identifiers. Attackers can exploit the unguarded RTMP callback endpoint to modify scheduled broadcast status fields by supplying fabricated stream keys matching the pattern -ps-<N>, silently canceling any scheduled live broadcast without credentials or authorization.
Score: 8.2/10 — Severidad: HIGH — Estado NIST: Received
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H
CWE-284
Publicado en NIST NVD.