Avid(AVideo)29.0 及更早版本存在一个信息泄露漏洞,位于 中。该漏洞允许已认证的推流用户枚举所有其他推流者当前活跃的再推流(restreams)的源流密钥和身份信息。该端点未能根据用户所有权对结果进行过滤,导致任何具备推流能力的用户都能访问所有账户的敏感传输凭证和推流者身份。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-86723 | 8.1 HIGH | AVideo LoginControl PGP Authentication Bypass via verifyChallenge |
| CVE-2026-86720 | 8.1 HIGH | WWBN AVideo Missing Authorization via resendRestreamer.json.php |
| CVE-2026-86722 | 8.1 HIGH | AVideo Authentication Bypass via SQL Cache Invalidation |
| CVE-2026-86728 | 7.5 HIGH | AVideo through 29.0 Unauthenticated Disclosure via epg.json.php |
| CVE-2026-86727 | 7.5 HIGH | AVideo through 29.0 Information Disclosure via stats.json.php |
| CVE-2026-86721 | 7.5 HIGH | AVideo through c3edcc274c Authorization Bypass via Session Cookie |
| CVE-2026-86729 | 7.4 HIGH | WWBN AVideo Unrestricted Authentication Attempts via get_api_preauthorize |
| CVE-2026-86718 | 7.1 HIGH | WWBN AVideo Cross-Site Request Forgery via deleteHistory.json.php |
| CVE-2026-86725 | 7.1 HIGH | AVideo SocialMediaPublisher Missing Authorization via add.json.php |
| CVE-2026-86724 | 6.5 MEDIUM | AVideo YPTWallet saveBalance.php Cross-Site Request Forgery |
| CVE-2026-86719 | 5.4 MEDIUM | WWBN AVideo CustomizeUser Cross-Site Request Forgery Session Hijacking |
No comments yet