Cross-Site Request Forgery in WWBN AVideo Affecting Video Publishing
CVE-2026-58003
7.1HIGH
What is CVE-2026-58003?
The vulnerability found in WWBN AVideo allows attackers to exploit the releaseVideoNow.json.php endpoint through cross-site request forgery. This occurs due to the absence of authenticity checks, enabling malicious GET requests that can manipulate the videos_id parameter of an administrator's session cookie. Consequently, this flaw can lead to unauthorized publication of embargoed videos, posing significant risks to video content security.
Affected Version(s)
AVideo 0 <= 9c39d8c8b4c1f75540788d6b391740852ceb0732
