WWBN AVideo 在 commit 9c39d8c8 版本中, 存在一个跨站请求伪造(CSRF)漏洞。该文件缺乏请求真实性验证,并接受 GET 请求。攻击者可在视频描述中嵌入一个 img 标签,当管理员访问该视频页面时,会导致视频所有权被转移至攻击者控制的账户。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-59808 | 8.8 HIGH | AVideo Authentication Bypass via Unkeyed Video Hash Disclosure |
| CVE-2026-59256 | 7.5 HIGH | WWBN AVideo Unbound Token Authorization Bypass via Gallery |
| CVE-2026-58003 | 7.1 HIGH | WWBN AVideo Cross-Site Request Forgery via releaseVideoNow.json.php |
| CVE-2026-58002 | 6.5 MEDIUM | WWBN AVideo Authorization Bypass via Users_affiliations add.json.php |
| CVE-2026-57944 | 5.4 MEDIUM | AVideo channelToGallery.json.php Cross-Site Request Forgery |
| CVE-2026-56380 | 5.3 MEDIUM | AVideo feed/index.php Exposure of Channel Owner Email Address |
No comments yet