PT-2026-79537 · Wwbn · Avideo
CVSS v3.1
5.7
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
WWBN AVideo versions prior to commit 9c39d8c8
Description
A cross-site request forgery (CSRF) issue exists in the 'objects/videoEditLight.php' endpoint. The system fails to perform request authenticity checks and incorrectly accepts GET requests. An attacker can exploit this by embedding an
img tag within a video description; when an administrator views the affected video page, the request is triggered, transferring video ownership to an account controlled by the attacker.Recommendations
Update WWBN AVideo to a version beyond commit 9c39d8c8.
Fix
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Avideo