AVideo Vulnerability in User Photo Upload Features
CVE-2026-43877
5.4MEDIUM
What is CVE-2026-43877?
The AVideo platform is susceptible to a Cross-Site Request Forgery vulnerability in its legacy profile-photo endpoint located at objects/userSavePhoto.php. This endpoint allows attackers to exploit the lack of CSRF protections and MIME validations. As a result, a malicious actor could lure a logged-in user to a fraudulent webpage, leading to unauthorized changes of the user's profile photo. Moreover, each forged request could also trigger a cache-clearing operation site-wide, amplifying the potential impact of this vulnerability. Users are encouraged to upgrade to a patched version as detailed in the security advisory.
Affected Version(s)
AVideo <= 29.0
