Critical severity9.8NVD Advisory· Published Jan 10, 2024· Updated Jun 17, 2026
CVE-2023-49599
CVE-2023-49599
Description
An insufficient entropy vulnerability exists in the salt generation functionality of WWBN AVideo dev master commit 15fed957fb. A specially crafted series of HTTP requests can lead to privilege escalation. An attacker can gather system information via HTTP requests and brute force the salt offline, leading to forging a legitimate password recovery code for the admin user.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
wwbn/avideoPackagist | <= 12.4 | — |
Affected products
3Patches
Vulnerability mechanics
References
5- talosintelligence.com/vulnerability_reports/TALOS-2023-1900nvdExploitThird Party AdvisoryWEB
- github.com/advisories/GHSA-wqcc-qf63-c2x4ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2023-49599ghsaADVISORY
- github.com/WWBN/AVideo/commit/15fed957fb64b4055158acfc449bd7974346edb5ghsaWEB
- www.talosintelligence.com/vulnerability_reports/TALOS-2023-1900nvd
News mentions
0No linked articles in our index yet.