Impact:
An attacker could execute remote code on a system running wwbn/avideo
Step to Reproduce:
My Videos tabhttps://demo.avideo.com/mvideos
Append a command to the url as a query string. eg. ?whoami
then click Save
This issue has been resolved in commit 236228f15