Impact
The flaw lies in sendEmail.json.php, which accepts requests without adequate origin checks or captcha validation. If an administrator is authenticated, an attacker can host a malicious page that, when loaded in the admin’s browser, forces the site to send emails from its contact address. The resulting messages have attacker‑controlled subject lines, bodies, and recipients, and they pass normal email authentication checks such as SPF, DKIM, and DMARC. This allows phishing campaigns and brand‑impersonation attacks that appear to come from the legitimate site.
Affected Systems
All installations of WWBN AVideo are potentially vulnerable, regardless of version, unless the vendor releases a patch or the endpoint is removed.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate risk profile, and although an EPSS score is not available, the vulnerability relies on an authenticated administrator’s session. Attackers need only trick those users into visiting a crafted web page. Since the vulnerability can create emails that bypass standard email‑authentication defenses, the potential for brand‑impersonation attacks is high. The issue is not currently listed in the CISA KEV catalog, but that does not diminish the impact to an organization that relies on this software.
OpenCVE Enrichment