Cross-Site Request Forgery Vulnerability in WWBN AVideo by WWBN
CVE-2022-29468

8.8HIGH

Key Information:

Vendor

Wwbn

Status
Vendor
CVE Published:
22 August 2022

What is CVE-2022-29468?

A cross-site request forgery (CSRF) vulnerability in WWBN AVideo allows attackers to exploit this flaw by sending specially-crafted HTTP requests. An authenticated user may unknowingly trigger the vulnerability, which can lead to unauthorized privilege escalation. This risk poses significant security implications for users of AVideo versions 11.6 and dev master commit 3f7c0364, highlighting the necessity for users to ensure robust security measures are in place.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

AVideo 11.6

AVideo dev master commit 3f7c0364

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

CVSS V3.0

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.