启用了 YPTSocket 插件的 AVideo 存在一个跨站脚本(XSS)漏洞,允许未认证的攻击者通过 websocket 回调机制,在其他用户的浏览器中执行任意 JavaScript 代码。攻击者可以构造特定的 socket 消息,使回调名称解析到诸如 这样的全局函数,这些函数会接受不受信任的数据并将其赋值给 ,从而在受害者的源(origin)中实现脚本执行,且无需身份验证或用户交互。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-86189 | 9.8 CRITICAL | WWBN AVideo Unauthenticated Path Traversal via notify.ffmpeg.json.php |
| CVE-2026-86190 | 9.1 CRITICAL | WWBN AVideo Broken Access Control via videoViewsInfo hash Parameter |
| CVE-2026-86186 | 6.5 MEDIUM | AVideo API Rate Limit Bypass via Bot User-Agent Header |
| CVE-2026-86187 | 5.9 MEDIUM | WWBN AVideo Weak PRNG Password Generation via External Login |
No comments yet