PT-2026-30713 · Wwbn · Avideo

·

CVE-2026-35180

·

Published

2026-04-06

·

Updated

2026-04-06

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions WWBN AVideo versions 26.0 and prior
Description WWBN AVideo, an open source video platform, has an issue in versions 26.0 and prior where the site customization endpoint at admin/customize settings nativeUpdate.json.php does not validate CSRF tokens. This allows a cross-origin POST request to overwrite the platform's logo with attacker-controlled content, as uploaded logo files are written to disk before the ORM's domain-based security check is performed. The SameSite=None cookie policy exacerbates this issue.
Recommendations Update to a version later than 26.0.

Exploit

Fix

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-35180
GHSA-5572-2JGX-FC7C

Affected Products

Avideo