PT-2026-84542 · Wwbn · Avideo
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
WWBN AVideo versions prior to commit 9c39d8c8
Description
An incomplete authentication bypass exists in the 'encryptPass.json.php' endpoint. This flaw allows unauthenticated attackers to compute valid HMAC (Hash-based Message Authentication Code) tokens using the public site URL and the current time. By computing
hash hmac with the site's base URL as the key, attackers can forge authentication tokens and submit arbitrary passwords to obtain encrypted hashes, which facilitates offline precomputation attacks against stolen password databases.Recommendations
Update WWBN AVideo to commit 9c39d8c8 or a later version.
As a temporary mitigation, restrict access to the 'encryptPass.json.php' endpoint.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Avideo