Impact
AVideo's Live component contains a CSRF flaw in plugin/Live/saveLive.php. The lack of forbidIfNotPost and forbidIfInvalidToken checks lets an attacker craft a malicious image tag that forces a logged‑in streamer to submit a POST request, causing their RTMP key, password, and title to be replaced. This lets the attacker hijack the broadcast and potentially view or disrupt the content.
Affected Systems
This issue affects the AVideo application from vendor WWBN. All releases that include commit c91b5975d contain the vulnerable code. No specific version range is listed, so affected installations are those deploying the vulnerable commit.
Risk and Exploitability
The CVSS score of 7.1 indicates moderate‑to‑high severity. EPSS data is not available, but the risk remains present because attackers can trigger the flaw remotely by luring an authenticated user to load a crafted image. The vulnerability is not listed in CISA's KEV catalog, yet it can still be abused in targeted attacks. The attack vector is a web‑based CSRF, requiring the victim's authenticated session to be active.
OpenCVE Enrichment