PT-2026-84993 · Avideo · Avideo
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
AVideo versions prior to commit c91b5975d
Description
A cross-site request forgery issue exists in the 'removePoster.php' endpoint. The application fails to implement
forbidIfNotPost or forbidIfInvalidToken checks, allowing attackers to use malicious image tags to trigger GET requests. This can result in the unauthorized deletion of live poster and thumbnail files belonging to authenticated users.Recommendations
Update AVideo to a version including commit c91b5975d or later.
Fix
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Avideo