PT-2026-94238 · Wwbn · Avideo
CVSS v3.1
7.3
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
WWBN AVideo through commit e01e41ecc
Description
A broken access control flaw exists in the 'objects/userVerifyEmail.php' endpoint. The script disables login requirements via the
$global['ignoreUserMustBeLoggedIn'] variable and accepts the users id parameter directly from the query string. It calls the User::sendVerificationLink() function without requiring a session, a CSRF token, a relationship check between the caller and the target, or the enforceRateLimit() function. Because the rate limit is tied to the caller's session, requests made without cookies are not limited. This allows an unauthenticated remote attacker to send an unlimited number of verification emails to any account ID and enumerate accounts and their verification status based on the JSON responses. Furthermore, the createVerificationCode() function triggers $user->setRecoverPass(), which saves a live password-recovery token to the targeted account. This token is sent in base64 format within the verification link and is accepted by the 'objects/userRecoverPassSave.json.php' endpoint as a valid credential for setting a new password.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Allocation of Resources Without Limits
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Avideo