A local file inclusion (LFI) vulnerability in Vedo Suite...
Moderate severity
Unreviewed
Published
Aug 6, 2025
to the GitHub Advisory Database
•
Updated Aug 7, 2025
Description
Published by the National Vulnerability Database
Aug 6, 2025
Published to the GitHub Advisory Database
Aug 6, 2025
Last updated
Aug 7, 2025
A local file inclusion (LFI) vulnerability in Vedo Suite version 2024.17 allows remote authenticated attackers to read arbitrary filesystem files by exploiting an unsanitized 'readfile()' function call in '/api_vedo/video/preview'.
References