Cross-Site Request Forgery Vulnerability in WWBN AVideo
CVE-2026-82647

5.3MEDIUM

Key Information:

Vendor

Wwbn

Status
Vendor
CVE Published:
30 August 2026

What is CVE-2026-82647?

AVideo by WWBN is susceptible to a cross-site request forgery vulnerability within the sendEmail.json.php endpoint. This flaw permits authenticated administrators to send emails using the site's contact address, circumventing origin checks and captcha validation. Attackers can exploit this vulnerability by creating malicious web pages that, when accessed by an authenticated admin, trigger the sending of emails with malicious content to any recipient, effectively passing SPF, DKIM, and DMARC checks. This can facilitate phishing attacks and brand impersonation, posing a serious threat to both the organization's reputation and user security.

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

rajivraj
.