AVideo 在 commit 9c39d8c8 中,channelToGallery.json.php 存在一个跨站请求伪造(CSRF)漏洞。攻击者可以通过向插件数据执行未经授权的写入操作,修改整个站点的画廊配置。攻击者可构造一个携带管理员会话 Cookie 的跨站 GET 请求,从而将任意频道提升为首页展示内容,或在不进行令牌验证的情况下删除精心策划的内容区域。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-59808 | 8.8 HIGH | AVideo Authentication Bypass via Unkeyed Video Hash Disclosure |
| CVE-2026-59256 | 7.5 HIGH | WWBN AVideo Unbound Token Authorization Bypass via Gallery |
| CVE-2026-58003 | 7.1 HIGH | WWBN AVideo Cross-Site Request Forgery via releaseVideoNow.json.php |
| CVE-2026-58002 | 6.5 MEDIUM | WWBN AVideo Authorization Bypass via Users_affiliations add.json.php |
| CVE-2026-58001 | 5.7 MEDIUM | WWBN AVideo Cross-Site Request Forgery via videoEditLight.php |
| CVE-2026-56380 | 5.3 MEDIUM | AVideo feed/index.php Exposure of Channel Owner Email Address |
No comments yet