在 commit c3edcc274c389816d434acadac07ee78eaf330c1 之前的 WWBN AVideo 中, 文件未对 的所有权进行验证,导致拥有 权限的已认证用户能够访问其他用户的再广播(restream)目的地。攻击者可以通过提供任意的 值,将他们的直播流推送到由受害者配置的再广播目的地,从而使用受害者的流密钥劫持其 YouTube、Facebook 或 Twitch 直播流。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-86723 | 8.1 HIGH | AVideo LoginControl PGP Authentication Bypass via verifyChallenge |
| CVE-2026-86722 | 8.1 HIGH | AVideo Authentication Bypass via SQL Cache Invalidation |
| CVE-2026-86728 | 7.5 HIGH | AVideo through 29.0 Unauthenticated Disclosure via epg.json.php |
| CVE-2026-86727 | 7.5 HIGH | AVideo through 29.0 Information Disclosure via stats.json.php |
| CVE-2026-86721 | 7.5 HIGH | AVideo through c3edcc274c Authorization Bypass via Session Cookie |
| CVE-2026-86729 | 7.4 HIGH | WWBN AVideo Unrestricted Authentication Attempts via get_api_preauthorize |
| CVE-2026-86718 | 7.1 HIGH | WWBN AVideo Cross-Site Request Forgery via deleteHistory.json.php |
| CVE-2026-86725 | 7.1 HIGH | AVideo SocialMediaPublisher Missing Authorization via add.json.php |
| CVE-2026-86726 | 6.5 MEDIUM | AVideo through 29.0 Information Disclosure via restreamsActive.json.php |
| CVE-2026-86724 | 6.5 MEDIUM | AVideo YPTWallet saveBalance.php Cross-Site Request Forgery |
| CVE-2026-86719 | 5.4 MEDIUM | WWBN AVideo CustomizeUser Cross-Site Request Forgery Session Hijacking |
No comments yet