CVE-2026-92580 | WWBN AVideo up to 29.0 CloneSite cloneClient.json.php str_replace Password os command injection

SecurityVulns

A vulnerability categorized as very critical has been discovered in WWBN AVideo up to 29.0. Impacted is the function str_replace of the file plugin/CloneSite/cloneClient.json.php of the component CloneSite. Executing a manipulation of the argument Password can lead to os command injection.

This vulnerability is handled as CVE-2026-92580. The attack can be executed remotely. There is not any exploit available.VulDB Recent EntriesRead More