Impact
WWBN AVideo does not validate the expiration of password recovery tokens in the userRecoverPassSave.json.php script, allowing an attacker who obtains a token to reset a target account’s password at any later time. This flaw enables full account takeover without the need for additional credentials. The flaw is categorized as CWE-613, reflecting an authentication bypass vulnerability. The high CVSS score of 9.3 indicates a critical impact on confidentiality, integrity, and availability of affected user accounts.
Affected Systems
All installations of WWBN AVideo are potentially affected; version information is not specified in the advisory, so any current or historical build must be reviewed for the presence of the unexpired token validation logic.
Risk and Exploitability
The CVSS rating of 9.3 and the lack of an expiration check make this vulnerability highly exploitable via the web interface. Although no EPSS score is available, the flaw allows attackers to use a single compromised token repeatedly, thereby elevating the likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog, but the potential for automated or manual abuse warrants immediate attention. Attackers need only an existing recovery token; no additional access or privileged permissions are required.
OpenCVE Enrichment