Cross-Site Request Forgery Vulnerability in WWBN AVideo Video Platform
CVE-2026-35181
4.3MEDIUM
What is CVE-2026-35181?
The WWBN AVideo video platform prior to version 26.0 is susceptible to Cross-Site Request Forgery (CSRF). The vulnerability lies in the player skin configuration endpoint located at admin/playerUpdate.json.php, which fails to validate CSRF tokens. As a result, malicious actors can exploit this oversight to perform unauthorized actions that alter the appearance of the video player across the entire platform. This risk is exacerbated by the use of SameSite=None cookies, allowing cross-origin requests to bypass security measures. The absence of domain-based security checks for the plugins table further compounds the issue, highlighting the need for immediate remediation.
Affected Version(s)
AVideo <= 26.0
