WWBN AVideo 在 中未验证密码恢复令牌的有效期,导致攻击者可以使用已过期的令牌无限期地重置账户密码。获得恢复令牌的攻击者可以在任意时间使用该令牌更改目标账户的密码,从而获得账户的完整访问权限。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-84479 | 9.1 CRITICAL | WWBN AVideo Authentication Bypass via User-Agent Header |
| CVE-2026-84482 | 8.8 HIGH | WWBN AVideo Cross-Site Request Forgery via get_domain() validation |
| CVE-2026-84187 | 8.2 HIGH | AVideo on_publish.php Missing Authentication Check via RTMP Callback |
| CVE-2026-83595 | 8.1 HIGH | AVideo Cross-Site Request Forgery via plugin/API/set.json.php |
| CVE-2026-84208 | 7.5 HIGH | AVideo User_Location Plugin Unauthenticated SQL Injection |
| CVE-2026-84476 | 7.5 HIGH | WWBN AVideo Authentication Bypass via X-Real-IP Header |
| CVE-2026-84478 | 7.3 HIGH | WWBN AVideo Unauthenticated Arbitrary Log File Deletion |
| CVE-2026-84481 | 6.9 MEDIUM | WWBN AVideo through 30.0 Information Disclosure via MobileManager |
| CVE-2026-84477 | 5.4 MEDIUM | AVideo Stored XSS via Live Schedule Title Description |
| CVE-2026-84483 | 5.3 MEDIUM | WWBN AVideo Unauthenticated Password Hash Oracle via encryptPass.json.php |
No comments yet