Cross-Site Request Forgery in AVideo by WWBN Allows Unauthorized Video Manipulation
CVE-2026-92582

7.1HIGH

Key Information:

Vendor

Wwbn

Status
Vendor
CVE Published:
16 September 2026

What is CVE-2026-92582?

AVideo versions up to 29.0 are vulnerable to cross-site request forgery due to insufficient validation of user input in the videoAddNew.json.php script. The vulnerability arises as a result of disabling automatic CSRF guards and untrusted request checks based solely on the presence of 'user' and 'pass' parameters. This oversight allows attackers to exploit authenticated sessions of legitimate users, enabling them to perform unauthorized actions like modifying video records, changing ownership, or altering access restrictions. Particularly concerning is the ability for attackers to affect videos under administrative rights, where critical permissions could be unbounded. No patch has been released for this vulnerability as of the advisory.

Affected Version(s)

AVideo 0 <= 29.0

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
Low
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

rajivraj
.