AVideo Vulnerability in User Photo Upload Features
CVE-2026-43877

5.4MEDIUM

Key Information:

Vendor

Wwbn

Status
Vendor
CVE Published:
11 May 2026

What is CVE-2026-43877?

The AVideo platform is susceptible to a Cross-Site Request Forgery vulnerability in its legacy profile-photo endpoint located at objects/userSavePhoto.php. This endpoint allows attackers to exploit the lack of CSRF protections and MIME validations. As a result, a malicious actor could lure a logged-in user to a fraudulent webpage, leading to unauthorized changes of the user's profile photo. Moreover, each forged request could also trigger a cache-clearing operation site-wide, amplifying the potential impact of this vulnerability. Users are encouraged to upgrade to a patched version as detailed in the security advisory.

Affected Version(s)

AVideo <= 29.0

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.