Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-56345— AVideo - Arbitrary User Session Hijacking via Meet Plugin uploadRecordedVideo Endpoint

CVSS 8.1 · High EPSS 0.45% · P38

Affected Version Matrix 1

VendorProductVersion RangeStatus
AVideoAVideo≤ 29.0affected
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2026-56345

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
AVideo - Arbitrary User Session Hijacking via Meet Plugin uploadRecordedVideo Endpoint
Source: CVE Program / CVE List V5
Vulnerability Description
AVideo through 29.0 contains an authorization bypass vulnerability in the Meet plugin's uploadRecordedVideo.json.php endpoint that derives the target users_id from the uploaded filename without verification. An attacker with knowledge of the Meet shared secret can craft a malicious file upload with a filename containing an arbitrary users_id to invoke passwordless User->login() and establish an authenticated session as any user including admin. Attackers can obtain the Meet shared secret through path-traversal vulnerabilities or timing attacks against checkToken.json.php, then POST a crafted file to uploadRecordedVideo.json.php with a filename like '1-anything.mp4' to hijack admin sessions and gain full account takeover.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
认证机制不恰当
Source: CVE Program / CVE List V5
Vulnerability Title
WWBN AVideo 授权问题漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
WWBN avideo是WWBN组织开源的一套视频内容管理系统。 WWBN AVideo 29.0及之前版本存在授权问题漏洞,该漏洞源于Meet插件中uploadRecordedVideo.json.php端点从上传文件名中提取目标users_id而未经验证,可能导致攻击者利用已知的Meet共享密钥,通过路径遍历或timing攻击获取共享密钥后,构造包含任意users_id的文件名上传,调用无密码User->login()建立已认证会话,进而劫持管理员会话并完全接管账户。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
AVideoAVideo 0 ~ 29.0 -

II. Public POCs for CVE-2026-56345

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-56345

登录查看更多情报信息。

Vendor Advisories for CVE-2026-56345 (2)

Same Patch Batch · AVideo · 2026-06-20 · 4 CVEs total

CVE-2026-563417.5 HIGHAVideo - Unauthenticated Access to Payment Log DataTables Endpoints via list.json.php
CVE-2026-563426.8 MEDIUMAVideo - Server-Side Request Forgery in Live/test.php via statsURL Parameter
CVE-2026-563466.5 MEDIUMAVideo - Unauthenticated PGP Message Decryption via decryptMessage.json.php Endpoint

IV. Related Vulnerabilities

V. Comments for CVE-2026-56345

No comments yet


Leave a comment