PT-2026-94238 · Wwbn · Avideo

·

CVE-2026-92915

·

Published

2026-09-17

·

Updated

2026-09-17

CVSS v3.1

7.3

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions WWBN AVideo through commit e01e41ecc
Description A broken access control flaw exists in the 'objects/userVerifyEmail.php' endpoint. The script disables login requirements via the $global['ignoreUserMustBeLoggedIn'] variable and accepts the users id parameter directly from the query string. It calls the User::sendVerificationLink() function without requiring a session, a CSRF token, a relationship check between the caller and the target, or the enforceRateLimit() function. Because the rate limit is tied to the caller's session, requests made without cookies are not limited. This allows an unauthenticated remote attacker to send an unlimited number of verification emails to any account ID and enumerate accounts and their verification status based on the JSON responses. Furthermore, the createVerificationCode() function triggers $user->setRecoverPass(), which saves a live password-recovery token to the targeted account. This token is sent in base64 format within the verification link and is accepted by the 'objects/userRecoverPassSave.json.php' endpoint as a valid credential for setting a new password.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Allocation of Resources Without Limits

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-92915
GHSA-RG4H-FCMM-8W26

Affected Products

Avideo