AVideo 29.0 及之前版本存在一个认证绕过漏洞,位于插件文件 。该漏洞使得未认证的用户能够访问实时流媒体密钥和私有 EPG(电子节目指南)日程。攻击者可以通过按顺序请求该端点(使用连续的用户或播放列表 ID),从而无需认证即可获取敏感凭证、服务器标识符以及完整的节目日程。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-86723 | 8.1 HIGH | AVideo LoginControl PGP Authentication Bypass via verifyChallenge |
| CVE-2026-86720 | 8.1 HIGH | WWBN AVideo Missing Authorization via resendRestreamer.json.php |
| CVE-2026-86722 | 8.1 HIGH | AVideo Authentication Bypass via SQL Cache Invalidation |
| CVE-2026-86727 | 7.5 HIGH | AVideo through 29.0 Information Disclosure via stats.json.php |
| CVE-2026-86721 | 7.5 HIGH | AVideo through c3edcc274c Authorization Bypass via Session Cookie |
| CVE-2026-86729 | 7.4 HIGH | WWBN AVideo Unrestricted Authentication Attempts via get_api_preauthorize |
| CVE-2026-86718 | 7.1 HIGH | WWBN AVideo Cross-Site Request Forgery via deleteHistory.json.php |
| CVE-2026-86725 | 7.1 HIGH | AVideo SocialMediaPublisher Missing Authorization via add.json.php |
| CVE-2026-86726 | 6.5 MEDIUM | AVideo through 29.0 Information Disclosure via restreamsActive.json.php |
| CVE-2026-86724 | 6.5 MEDIUM | AVideo YPTWallet saveBalance.php Cross-Site Request Forgery |
| CVE-2026-86719 | 5.4 MEDIUM | WWBN AVideo CustomizeUser Cross-Site Request Forgery Session Hijacking |
No comments yet