Vulnerability Description
AVideo/YouPHPTube 10.0 and prior is affected by Insecure file write. An administrator privileged user is able to write files on filesystem using flag and code variables in file save.php.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Youphptube | Youphptube | <= 10.0 |
Related Weaknesses (CWE)
References
- http://avideoyouphptube.comBroken LinkProductURL Repurposed
- https://synacktiv.comProduct
- https://www.synacktiv.com/sites/default/files/2021-01/YouPHPTube_Multiple_VulnerExploitVendor Advisory
- http://avideoyouphptube.comBroken LinkProductURL Repurposed
- https://synacktiv.comProduct
- https://www.synacktiv.com/sites/default/files/2021-01/YouPHPTube_Multiple_VulnerExploitVendor Advisory
FAQ
What is CVE-2021-25877?
CVE-2021-25877 is a vulnerability with a CVSS score of 7.2 (HIGH). AVideo/YouPHPTube 10.0 and prior is affected by Insecure file write. An administrator privileged user is able to write files on filesystem using flag and code variables in file save.php.
How severe is CVE-2021-25877?
CVE-2021-25877 has been rated HIGH with a CVSS base score of 7.2/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-25877?
Check the references section above for vendor advisories and patch information. Affected products include: Youphptube Youphptube.