CSRF Vulnerability in WWBN AVideo Affects User Interaction Features
CVE-2026-40928

5.4MEDIUM

Key Information:

Vendor

Wwbn

Status
Vendor
CVE Published:
21 April 2026

What is CVE-2026-40928?

A vulnerability exists in WWBN AVideo, an open-source video platform, where multiple JSON endpoints under the objects/ directory allow state-changing requests from unauthenticated sources. This weakness arises because changes are made based on the session of the logged-in user without adequate checks for CSRF tokens, origin, or referer validation. An attacker can leverage this flaw by tricking a user into loading a malicious HTML resource, resulting in unintended actions such as altering a comment's like/dislike status, posting new comments with pre-selected content, or deleting assets from categories where the user has management rights. This exploit can be executed through simple HTML elements, significantly compromising user account integrity and interaction within the platform.

Affected Version(s)

AVideo <= 29.0

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.