AVideo 软件版本 29.0 及之前版本存在一个未经身份验证的 SQL 注入漏洞,位于 User_Location 插件的 和 端点。其中, 和 GET 参数被直接拼接到 SQL 查询语句中,未进行转义或使用预编译语句(prepared statements),这使得未经身份验证的攻击者可以通过 UNION 型 SQL 注入读取数据库中的任意内容,包括密码哈希值和其他敏感数据。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-84480 | 9.8 CRITICAL | WWBN AVideo Password Recovery Token Expiration Bypass |
| CVE-2026-84479 | 9.1 CRITICAL | WWBN AVideo Authentication Bypass via User-Agent Header |
| CVE-2026-84482 | 8.8 HIGH | WWBN AVideo Cross-Site Request Forgery via get_domain() validation |
| CVE-2026-84187 | 8.2 HIGH | AVideo on_publish.php Missing Authentication Check via RTMP Callback |
| CVE-2026-83595 | 8.1 HIGH | AVideo Cross-Site Request Forgery via plugin/API/set.json.php |
| CVE-2026-84476 | 7.5 HIGH | WWBN AVideo Authentication Bypass via X-Real-IP Header |
| CVE-2026-84478 | 7.3 HIGH | WWBN AVideo Unauthenticated Arbitrary Log File Deletion |
| CVE-2026-84481 | 6.9 MEDIUM | WWBN AVideo through 30.0 Information Disclosure via MobileManager |
| CVE-2026-84477 | 5.4 MEDIUM | AVideo Stored XSS via Live Schedule Title Description |
| CVE-2026-84483 | 5.3 MEDIUM | WWBN AVideo Unauthenticated Password Hash Oracle via encryptPass.json.php |
No comments yet