Cross-Site Request Forgery Vulnerability in WWBN AVideo Video Platform
CVE-2026-35181

4.3MEDIUM

Key Information:

Vendor

Wwbn

Status
Vendor
CVE Published:
6 April 2026

What is CVE-2026-35181?

The WWBN AVideo video platform prior to version 26.0 is susceptible to Cross-Site Request Forgery (CSRF). The vulnerability lies in the player skin configuration endpoint located at admin/playerUpdate.json.php, which fails to validate CSRF tokens. As a result, malicious actors can exploit this oversight to perform unauthorized actions that alter the appearance of the video player across the entire platform. This risk is exacerbated by the use of SameSite=None cookies, allowing cross-origin requests to bypass security measures. The absence of domain-based security checks for the plugins table further compounds the issue, highlighting the need for immediate remediation.

Affected Version(s)

AVideo <= 26.0

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.