WWBN AVideo 的 存在跨站请求伪造(CSRF)漏洞,使得经过身份验证的站点管理员能够通过绕过源检查(origin check)和验证码(captcha)验证,从站点的发件邮箱发送邮件。攻击者可以构造一个恶意网页,当已认证的管理员访问该网页时,该页面会向任意收件人发送邮件,且邮件的主题和内容由攻击者控制,并能通过 SPF/DKIM/DMARC 验证,从而用于钓鱼和品牌仿冒攻击。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-82645 | 8.6 HIGH | AVideo Unauthenticated Stream Credential Disclosure via Forgeable Token |
| CVE-2026-82644 | 7.5 HIGH | WWBN AVideo Brute-force Rate Limiting Bypass via Missing User-Agent |
| CVE-2026-82648 | 7.1 HIGH | WWBN AVideo SSRF Filter Bypass via NAT64 Hex Address |
| CVE-2026-82643 | 6.5 MEDIUM | WWBN AVideo Unauthenticated Rate Limit Bypass via preauthorize.json.php |
| CVE-2026-82646 | 6.1 MEDIUM | WWBN AVideo Unauthenticated Reflected XSS via url2Embed.json.php |
No comments yet