Cross-Site Request Forgery Vulnerability in WWBN AVideo
CVE-2026-82647
5.3MEDIUM
What is CVE-2026-82647?
AVideo by WWBN is susceptible to a cross-site request forgery vulnerability within the sendEmail.json.php endpoint. This flaw permits authenticated administrators to send emails using the site's contact address, circumventing origin checks and captcha validation. Attackers can exploit this vulnerability by creating malicious web pages that, when accessed by an authenticated admin, trigger the sending of emails with malicious content to any recipient, effectively passing SPF, DKIM, and DMARC checks. This can facilitate phishing attacks and brand impersonation, posing a serious threat to both the organization's reputation and user security.
