CVE-2023-25313: AVideo contains Command injection when embedding a video link

Severity: Critical

CVSS Score: 9.7

OS injection vulnerability in World Wide Broadcast Network AVideo version before 12.4, allows attackers to execute arbitrary code via the video link field to the Embed a video link feature.