CSRF Vulnerability in WWBN AVideo Affects User Interaction Features
CVE-2026-40928
What is CVE-2026-40928?
A vulnerability exists in WWBN AVideo, an open-source video platform, where multiple JSON endpoints under the objects/ directory allow state-changing requests from unauthenticated sources. This weakness arises because changes are made based on the session of the logged-in user without adequate checks for CSRF tokens, origin, or referer validation. An attacker can leverage this flaw by tricking a user into loading a malicious HTML resource, resulting in unintended actions such as altering a comment's like/dislike status, posting new comments with pre-selected content, or deleting assets from categories where the user has management rights. This exploit can be executed through simple HTML elements, significantly compromising user account integrity and interaction within the platform.
Affected Version(s)
AVideo <= 29.0
