AVideo(截至提交 9c39d8c8)在 feed/index.php 中存在一个信息泄露漏洞,允许未经身份验证的攻击者通过提供公共频道名称参数,获取频道所有者的电子邮件地址。攻击者可以通过遍历所有公共频道名称,并从 RSS 元素中的 itunes:email 和 itunes:author 字段提取电子邮件地址,从而枚举所有创作者的邮箱。此漏洞可被用于实施账户接管攻击和钓鱼活动。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-59808 | 8.8 HIGH | AVideo Authentication Bypass via Unkeyed Video Hash Disclosure |
| CVE-2026-59256 | 7.5 HIGH | WWBN AVideo Unbound Token Authorization Bypass via Gallery |
| CVE-2026-58003 | 7.1 HIGH | WWBN AVideo Cross-Site Request Forgery via releaseVideoNow.json.php |
| CVE-2026-58002 | 6.5 MEDIUM | WWBN AVideo Authorization Bypass via Users_affiliations add.json.php |
| CVE-2026-58001 | 5.7 MEDIUM | WWBN AVideo Cross-Site Request Forgery via videoEditLight.php |
| CVE-2026-57944 | 5.4 MEDIUM | AVideo channelToGallery.json.php Cross-Site Request Forgery |
No comments yet