Impact
WWBN AVideo contains a cross‑site request forgery flaw in the get_domain() and isSameDomain() functions that do not correctly validate referer origins. An attacker can supply requests from sibling subdomains or malformed long‑gTLD domains to trick the application into treating the request as legitimate. This leads to the ability to perform administrative ObjectYPT writes, including changes to live server configuration, potentially compromising confidentiality, integrity, and availability of the system.
Affected Systems
The affected product is WWBN AVideo, specifically the code base at commit 9c39d8c8. Users of this version are vulnerable and should verify the version in use against the commit hash or reviewed patch notes.
Risk and Exploitability
The CVSS score of 8.7 indicates a high severity vulnerability. No EPSS score is available, and the flaw is not listed in CISA KEV catalog. The likely attack vector is a forged request originating from a controlled subdomain or specially crafted domain name that bypasses domain validation, allowing an unauthenticated attacker to perform privileged changes.
OpenCVE Enrichment