当客户端发送带有“bot”(机器人)User-Agent 请求头的请求时,AVideo 的 API 未强制执行速率限制,使得攻击者能够绕过所有八种受保护操作的速率限制,包括登录暴力破解防护。攻击者可以通过发送带有“bot” User-Agent 头的请求来禁用速率限制,从而从单一 IP 地址对任意账户进行无限制的密码猜测尝试。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-86189 | 9.8 CRITICAL | WWBN AVideo Unauthenticated Path Traversal via notify.ffmpeg.json.php |
| CVE-2026-86190 | 9.1 CRITICAL | WWBN AVideo Broken Access Control via videoViewsInfo hash Parameter |
| CVE-2026-86188 | 7.2 HIGH | AVideo YPTSocket Plugin Unauthenticated Cross-Site Scripting |
| CVE-2026-86187 | 5.9 MEDIUM | WWBN AVideo Weak PRNG Password Generation via External Login |
No comments yet