Impact
The vulnerability is a cross‑site request forgery in the playlistRemove.php script of WWBN AVideo, identified by commit c3edcc274c389816d434acadac07ee78eaf330c1. Because CSRF checks are omitted, an attacker can craft a malicious form that posts to /playlistRemove.php while a victim is logged in, causing the victim’s playlist to be deleted. This results services, and represents a medium‑to‑high risk authentication bypass flaw (CWE‑352).
Affected Systems
The issue affects all deployments of WWBN AVideo that include the unpatched playlistRemove.php handler. No of not applied the fix is vulnerable.
Risk and Exploitability
The CVSS score of 7.1 indicates a moderately high impact, and the lack of an EPSS score means there is currently no publicly known exploitation rate. The vulnerability is not listed in the CISA KEV catalog, but because the vector requires a logged‑in victim, attackers can target users by hosting a malicious page that the victim visits. Exploitation relies on the victim’s authenticated session cookie being sent automatically by the browser, so an attacker with social engineering or phishing abilities could readily trigger the deletion. The seriousness stems from data loss and the ease of the attack.
OpenCVE Enrichment