Cross-Site Request Forgery in WWBN AVideo
CVE-2026-84482

8.7HIGH

Key Information:

Vendor

Wwbn

Status
Vendor
CVE Published:
1 September 2026

What is CVE-2026-84482?

WWBN AVideo contains a cross-site request forgery vulnerability in its get_domain() and isSameDomain() functions. This flaw arises from inadequate validation of referer origins, which may permit an attacker to generate forged requests from sibling subdomains or improperly formatted long-gTLD origins. Through this exploit, malicious actors could perform unauthorized administrative actions, including sensitive modifications to the server configuration, potentially compromising the integrity and security of the AVideo installation.

Affected Version(s)

AVideo 0 <= 9c39d8c8b4c1f75540788d6b391740852ceb0732

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

santhreal
.