Incomplete Authentication Bypass in WWBN AVideo Web Application
CVE-2026-84483
6.9MEDIUM
What is CVE-2026-84483?
AVideo, developed by WWBN, has a significant vulnerability due to an incomplete authentication bypass located in 'encryptPass.json.php'. This flaw enables unauthenticated attackers to generate valid HMAC tokens by leveraging the public site URL and the current time. By exploiting this issue, attackers are able to forge authentication tokens, allowing them to execute offline precomputation attacks against hashed password databases. This vulnerability poses a serious risk to the security of user accounts and data integrity within the application.
Affected Version(s)
AVideo 0 <= 9c39d8c8b4c1f75540788d6b391740852ceb0732
