Description
WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a cross-site request forgery vulnerability in playlistRemove.php that allows attackers to delete playlists by skipping CSRF protection checks. Attackers can craft a malicious form that submits a POST request to playlistRemove.php, causing a victim's playlist to be deleted when they visit the attacker's page while logged in.
Published: 2026-09-11
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Playlist Deletion
Action: Patch ASAP
AI Analysis

Impact

The vulnerability is a cross‑site request forgery in the playlistRemove.php script of WWBN AVideo, identified by commit c3edcc274c389816d434acadac07ee78eaf330c1. Because CSRF checks are omitted, an attacker can craft a malicious form that posts to /playlistRemove.php while a victim is logged in, causing the victim’s playlist to be deleted. This results services, and represents a medium‑to‑high risk authentication bypass flaw (CWE‑352).

Affected Systems

The issue affects all deployments of WWBN AVideo that include the unpatched playlistRemove.php handler. No of not applied the fix is vulnerable.

Risk and Exploitability

The CVSS score of 7.1 indicates a moderately high impact, and the lack of an EPSS score means there is currently no publicly known exploitation rate. The vulnerability is not listed in the CISA KEV catalog, but because the vector requires a logged‑in victim, attackers can target users by hosting a malicious page that the victim visits. Exploitation relies on the victim’s authenticated session cookie being sent automatically by the browser, so an attacker with social engineering or phishing abilities could readily trigger the deletion. The seriousness stems from data loss and the ease of the attack.

Generated by OpenCVE AI on September 11, 2026 at 14:06 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest official AVideo release that contains the CSRF protection fix for playlistRemove.php.
  • If an update is not yet available, temporarily disable the playlist removal route or block POST requests to playlistRemove.php via web‑server configuration.
  • Add a CSRF token check to playlistRemove.php or enable the framework’s CSRF middleware if possible.
  • Educate users to avoid visiting unknown sites while authenticated to reduce the risk of accidental deletion.
  • Monitor logs for unexpected playlist deletions to detect potential exploitation.

Generated by OpenCVE AI on September 11, 2026 at 14:06 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 11 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 11 Sep 2026 11:30:00 +0000

Type Values Removed Values Added
Description WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a cross-site request forgery vulnerability in playlistRemove.php that allows attackers to delete playlists by skipping CSRF protection checks. Attackers can craft a malicious form that submits a POST request to playlistRemove.php, causing a victim's playlist to be deleted when they visit the attacker's page while logged in.
Title WWBN AVideo Cross-Site Request Forgery via playlistRemove.php
First Time appeared Wwbn
Wwbn avideo
Weaknesses CWE-352
CPEs cpe:2.3:a:wwbn:avideo:-:*:*:*:*:*:*:*
Vendors & Products Wwbn
Wwbn avideo
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N'}

cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-11T14:01:07.925Z

Reserved: 2026-09-11T10:51:31.663Z

Link: CVE-2026-89245

cve-icon Vulnrichment

Updated: 2026-09-11T14:01:01.138Z

cve-icon NVD

Status : Deferred

Published: 2026-09-11T12:16:54.270

Modified: 2026-09-11T15:21:12.850

Link: CVE-2026-89245

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T16:45:14Z

Weaknesses
  • CWE-352

    Cross-Site Request Forgery (CSRF)