在 commit c3edcc274c389816d434acadac07ee78eaf330c1 中的 AVideo 存在一个认证绕过漏洞:sqlDAL 会缓存空结果集,而 writeSql 从未使这些缓存失效。拥有有效密码的攻击者可以在新设备上绕过基于邮箱的双因素认证,因为陈旧的空结果集缓存导致确认码哈希值生成失败。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-86723 | 8.1 HIGH | AVideo LoginControl PGP Authentication Bypass via verifyChallenge |
| CVE-2026-86720 | 8.1 HIGH | WWBN AVideo Missing Authorization via resendRestreamer.json.php |
| CVE-2026-86728 | 7.5 HIGH | AVideo through 29.0 Unauthenticated Disclosure via epg.json.php |
| CVE-2026-86727 | 7.5 HIGH | AVideo through 29.0 Information Disclosure via stats.json.php |
| CVE-2026-86721 | 7.5 HIGH | AVideo through c3edcc274c Authorization Bypass via Session Cookie |
| CVE-2026-86729 | 7.4 HIGH | WWBN AVideo Unrestricted Authentication Attempts via get_api_preauthorize |
| CVE-2026-86718 | 7.1 HIGH | WWBN AVideo Cross-Site Request Forgery via deleteHistory.json.php |
| CVE-2026-86725 | 7.1 HIGH | AVideo SocialMediaPublisher Missing Authorization via add.json.php |
| CVE-2026-86726 | 6.5 MEDIUM | AVideo through 29.0 Information Disclosure via restreamsActive.json.php |
| CVE-2026-86724 | 6.5 MEDIUM | AVideo YPTWallet saveBalance.php Cross-Site Request Forgery |
| CVE-2026-86719 | 5.4 MEDIUM | WWBN AVideo CustomizeUser Cross-Site Request Forgery Session Hijacking |
No comments yet