WWBN AVideo 在验证受信任代理之前未对 和 头进行校验,这使得攻击者能够伪造由 使用的客户端地址。攻击者可以通过在每个请求中轮换这些头的值,从而绕过登录频率限制,并进行无限次的凭证猜测攻击。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-84480 | 9.8 CRITICAL | WWBN AVideo Password Recovery Token Expiration Bypass |
| CVE-2026-84479 | 9.1 CRITICAL | WWBN AVideo Authentication Bypass via User-Agent Header |
| CVE-2026-84482 | 8.8 HIGH | WWBN AVideo Cross-Site Request Forgery via get_domain() validation |
| CVE-2026-84187 | 8.2 HIGH | AVideo on_publish.php Missing Authentication Check via RTMP Callback |
| CVE-2026-83595 | 8.1 HIGH | AVideo Cross-Site Request Forgery via plugin/API/set.json.php |
| CVE-2026-84208 | 7.5 HIGH | AVideo User_Location Plugin Unauthenticated SQL Injection |
| CVE-2026-84478 | 7.3 HIGH | WWBN AVideo Unauthenticated Arbitrary Log File Deletion |
| CVE-2026-84481 | 6.9 MEDIUM | WWBN AVideo through 30.0 Information Disclosure via MobileManager |
| CVE-2026-84477 | 5.4 MEDIUM | AVideo Stored XSS via Live Schedule Title Description |
| CVE-2026-84483 | 5.3 MEDIUM | WWBN AVideo Unauthenticated Password Hash Oracle via encryptPass.json.php |
No comments yet