WWBN AVideo(在提交版本 9c39d8c8b4c1f75540788d6b391740852ceb0732 中)存在一个授权绕过漏洞,位于 Users_affiliations/add.json.php 接口。该漏洞允许已认证用户通过伪造对方同意的时间戳,生成虚假的两方同意记录。攻击者可利用此机制创建状态为 'a' 的虚假隶属关系,随后通过 videoAddNew.json.php 接口将视频所有权重新分配给任意用户。该接口错误地将虚假隶属关系视为合法授权依据,从而导致视频所有权被非法转移。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-59808 | 8.8 HIGH | AVideo Authentication Bypass via Unkeyed Video Hash Disclosure |
| CVE-2026-59256 | 7.5 HIGH | WWBN AVideo Unbound Token Authorization Bypass via Gallery |
| CVE-2026-58003 | 7.1 HIGH | WWBN AVideo Cross-Site Request Forgery via releaseVideoNow.json.php |
| CVE-2026-58001 | 5.7 MEDIUM | WWBN AVideo Cross-Site Request Forgery via videoEditLight.php |
| CVE-2026-57944 | 5.4 MEDIUM | AVideo channelToGallery.json.php Cross-Site Request Forgery |
| CVE-2026-56380 | 5.3 MEDIUM | AVideo feed/index.php Exposure of Channel Owner Email Address |
No comments yet