Cross-Site Request Forgery in AVideo by WWBN Allows Unauthorized Video Manipulation
CVE-2026-92582
What is CVE-2026-92582?
AVideo versions up to 29.0 are vulnerable to cross-site request forgery due to insufficient validation of user input in the videoAddNew.json.php script. The vulnerability arises as a result of disabling automatic CSRF guards and untrusted request checks based solely on the presence of 'user' and 'pass' parameters. This oversight allows attackers to exploit authenticated sessions of legitimate users, enabling them to perform unauthorized actions like modifying video records, changing ownership, or altering access restrictions. Particularly concerning is the ability for attackers to affect videos under administrative rights, where critical permissions could be unbounded. No patch has been released for this vulnerability as of the advisory.
Affected Version(s)
AVideo 0 <= 29.0
