AVideo(在提交版本 9c39d8c8 之前)存在一个身份验证绕过漏洞。该漏洞中, 函数通过 返回任意视频的 凭证,而未进行所有权验证;随后, 函数将该哈希值转换为无需密码的登录方式,使攻击者得以冒充视频所有者。具有上传权限的攻击者可以通过省略 参数来获取管理员的 ,然后在未经身份验证的请求中使用该哈希值,从而获得管理员会话访问权限,并修改系统配置。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-59256 | 7.5 HIGH | WWBN AVideo Unbound Token Authorization Bypass via Gallery |
| CVE-2026-58003 | 7.1 HIGH | WWBN AVideo Cross-Site Request Forgery via releaseVideoNow.json.php |
| CVE-2026-58002 | 6.5 MEDIUM | WWBN AVideo Authorization Bypass via Users_affiliations add.json.php |
| CVE-2026-58001 | 5.7 MEDIUM | WWBN AVideo Cross-Site Request Forgery via videoEditLight.php |
| CVE-2026-57944 | 5.4 MEDIUM | AVideo channelToGallery.json.php Cross-Site Request Forgery |
| CVE-2026-56380 | 5.3 MEDIUM | AVideo feed/index.php Exposure of Channel Owner Email Address |
No comments yet