Impact
AVideo exposes a cross‑site request forgery flaw in the plugin/API/set.json.php endpoint that allows an attacker to issue crafted GET requests to perform state‑changing operations such as deleting videos, deactivating accounts, or modifying playlists without any user interaction. The vulnerability bypasses the intended CSRF protections and lets the attacker direct a victim’s browser to a malicious URL containing API parameters, thereby pushing the undesired changes to the application.
Affected Systems
The affected product is AVideo from the vendor WWBN. The advisory does not list specific affected versions, indicating that all publicly available releases may be vulnerable until the vendor releases a fix. The weakness relies on the plugin/API set.json.php endpoint being exposed, so the scope reaches the entire system’s API layer.
Risk and Exploitability
Based on the description, the attack vector is inferred to be a crafted URL that lures a victim’s browser into executing a GET request to the vulnerable endpoint. The CVSS score of 7.2 signals a high risk level. No EPSS score is available and the vulnerability is not listed in CISA’s KEV catalog. Attackers can exploit the flaw by fabricating that malicious URL and luring a logged‑in user to visit it; this requires no additional privileges and minimal user interaction, making the attack path straightforward and the potential impact considerable for organizations running AVideo.
OpenCVE Enrichment