PT-2026-94099 · Avideo · Avideo

·

CVE-2026-92582

·

Published

2026-09-16

·

Updated

2026-09-16

CVSS v3.1

7.1

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:N
Name of the Vulnerable Software and Affected Versions AVideo versions prior to 29.0 (commit e01e41ecc)
Description Cross-site request forgery occurs because the endpoint 'objects/videoAddNew.json.php' disables the automatic CSRF guard ($global['skipAutoCSRFCheck']) and the untrusted-request check ($global['bypassSameDomainCheck']) when the user and pass parameters are present in the request. These values are read from $ REQUEST without validation, allowing an attacker to include them in a cross-site request query string. Since the function User::loginFromRequestIfNotLogged() returns immediately if a session already exists, an authenticated victim satisfies the check while the attacker's credentials are ignored. This allows an attacker to lure users with upload rights to a crafted page and submit cross-origin requests to modify video records, including setUsers id for ownership transfer, can download, can share, only for paid, video password, rating, status, creation date, and view count. Users with administrator or Permissions::canAdminVideos() rights can have any video on the site altered, including the removal of group restrictions from private content.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability. As a temporary workaround, restrict access to the 'objects/videoAddNew.json.php' endpoint to minimize the risk of exploitation.

Exploit

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-92582
GHSA-QF9P-JHX7-RHMF

Affected Products

Avideo