WWBN AVideo 在提交 9c39d8c8 中存在一个授权绕过漏洞。该漏洞中, 方法在生成令牌时未将其与用户身份或用途绑定;同时, 会将有效的令牌颁发给未经验证身份的访客。攻击者可以从 Gallery 端点获取一个令牌,并利用该令牌绕过其他子系统(如 )中的授权检查,从而访问受限的视频内容。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-59808 | 8.8 HIGH | AVideo Authentication Bypass via Unkeyed Video Hash Disclosure |
| CVE-2026-58003 | 7.1 HIGH | WWBN AVideo Cross-Site Request Forgery via releaseVideoNow.json.php |
| CVE-2026-58002 | 6.5 MEDIUM | WWBN AVideo Authorization Bypass via Users_affiliations add.json.php |
| CVE-2026-58001 | 5.7 MEDIUM | WWBN AVideo Cross-Site Request Forgery via videoEditLight.php |
| CVE-2026-57944 | 5.4 MEDIUM | AVideo channelToGallery.json.php Cross-Site Request Forgery |
| CVE-2026-56380 | 5.3 MEDIUM | AVideo feed/index.php Exposure of Channel Owner Email Address |
No comments yet