Impact
AVideo versions up to 29.0 contain a flaw in objects/videoAddNew.json.php that bypasses the application’s automatic CSRF guard and an untrusted‑request check. The code enables the bypass only when the request carries 'user' and 'pass' parameters, which are read directly from the request without validation. When an authenticated user has an existing session, the login routine skips processing the supplied credentials, allowing the attacker to inject arbitrary values into the call. This permits a range of video‑level changes such as ownership transfer, removal of group restrictions, download and share settings, status updates, and view counts. The impact is a loss of confidentiality, integrity and availability of video content for users with upload or administrator rights.
Affected Systems
The affected product is WWBN AVideo, specifically all releases through version 29.0 (commit e01e41ecc). No patched version is available at the time of the advisory, so all deployments of this product within the stated version range remain vulnerable.
Risk and Exploitability
The CVSS score is 7.1, indicating a high severity. The EPSS score is listed as "< 1%", meaning exploitation probability is very low but not zero. The vulnerability is not currently listed in the CISA KEV catalog. The most likely attack vector involves an attacker delivering a crafted page that lures an authenticated user—who possesses upload rights—to load the page. The user’s session cookie satisfies the authentication check, and the attacker’s supplied 'user' and 'pass' parameters are ignored, enabling the attacker to perform privileged video modifications from a cross‑origin context.
OpenCVE Enrichment