WWBN AVideo 在 中存在路径遍历漏洞,该漏洞允许未经身份验证的攻击者通过在 参数中提供由调用方指定的路径,从而将文件写入任意位置。攻击者可以重放任何先前颁发的密文作为 令牌(该令牌会被解密但从未进行有效性校验),以此绕过身份验证,并将文件写入应用程序根目录及其子目录。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-86190 | 9.1 CRITICAL | WWBN AVideo Broken Access Control via videoViewsInfo hash Parameter |
| CVE-2026-86188 | 7.2 HIGH | AVideo YPTSocket Plugin Unauthenticated Cross-Site Scripting |
| CVE-2026-86186 | 6.5 MEDIUM | AVideo API Rate Limit Bypass via Bot User-Agent Header |
| CVE-2026-86187 | 5.9 MEDIUM | WWBN AVideo Weak PRNG Password Generation via External Login |
No comments yet