WWBN AVideo 截至提交 e01e41ecc(目前尚无已修补的版本)在 中存在一个访问控制失效缺陷。该脚本禁用了登录要求(设置 ),直接从查询字符串中获取 ,并在无会话要求、无 CSRF/全局令牌、无调用者与目标之间关系校验、且未调用 的情况下调用 。唯一设计的限流机制仅基于调用者自身的会话键控,因此不含 Cookie 的请求将不受任何限制。 因此,未经身份验证的远程攻击者可以向任意账户 ID 触发发送任意数量的验证邮件,并可通过三种不同的 JSON 响应(“验证邮件已发送”、“已验证”、“未知错误”)来枚
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-92914 | 8.1 HIGH | AVideo LoginControl PGP Second Factor Authentication Bypass |
| CVE-2026-92913 | 7.4 HIGH | AVideo Weak PRNG Activation Code Authentication Bypass |
| CVE-2026-92912 | 6.5 MEDIUM | AVideo Cryptographically Weak PRNG via uniqid Stream Key |
No comments yet