Description
AVideo (WWBN/AVideo) through 29.0 (commit e01e41ecc) is vulnerable to cross-site request forgery. objects/videoAddNew.json.php disables AVideo's automatic CSRF guard ($global['skipAutoCSRFCheck']) and the untrusted-request check ($global['bypassSameDomainCheck']) merely because 'user' and 'pass' parameters are present in the request; the values are never validated and are read from $_REQUEST, so an attacker can supply them in the query string of a cross-site request. Because User::loginFromRequestIfNotLogged() returns immediately when a session already exists, a victim who is authenticated by cookie satisfies the check while the attacker-supplied credentials are discarded. An attacker who lures an authenticated user with upload rights to visit a crafted page can therefore submit cross-origin requests that modify video records — including ownership transfer (setUsers_id), deletion of user-group access restrictions, can_download, can_share, only_for_paid, video_password, rating, status, creation date, and view count. For a victim with administrator or Permissions::canAdminVideos() rights, any video on the site can be altered, including removing group restrictions from private content. No patched version was available at the time of the advisory.
Published: 2026-09-16
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Cross‑Site Request Forgery allowing unauthorized modification of video records and access‑control bypass
Action: Assess Impact
AI Analysis

Impact

AVideo versions up to 29.0 contain a flaw in objects/videoAddNew.json.php that bypasses the application’s automatic CSRF guard and an untrusted‑request check. The code enables the bypass only when the request carries 'user' and 'pass' parameters, which are read directly from the request without validation. When an authenticated user has an existing session, the login routine skips processing the supplied credentials, allowing the attacker to inject arbitrary values into the call. This permits a range of video‑level changes such as ownership transfer, removal of group restrictions, download and share settings, status updates, and view counts. The impact is a loss of confidentiality, integrity and availability of video content for users with upload or administrator rights.

Affected Systems

The affected product is WWBN AVideo, specifically all releases through version 29.0 (commit e01e41ecc). No patched version is available at the time of the advisory, so all deployments of this product within the stated version range remain vulnerable.

Risk and Exploitability

The CVSS score is 7.1, indicating a high severity. The EPSS score is listed as "< 1%", meaning exploitation probability is very low but not zero. The vulnerability is not currently listed in the CISA KEV catalog. The most likely attack vector involves an attacker delivering a crafted page that lures an authenticated user—who possesses upload rights—to load the page. The user’s session cookie satisfies the authentication check, and the attacker’s supplied 'user' and 'pass' parameters are ignored, enabling the attacker to perform privileged video modifications from a cross‑origin context.

Generated by OpenCVE AI on September 18, 2026 at 05:24 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Disable the global settings that bypass CSRF protection on the affected endpoint, ensuring automatic CSRF checks remain active
  • Restrict 'videoAddNew.json.php' to authenticated sessions that have valid CSRF tokens and remove the ability to pass arbitrary 'user' and 'pass' parameters
  • Limit upload and video‑edit permissions to only the necessary privileged accounts and review group access controls
  • Apply a temporary web‑application‑firewall rule to block external requests to the vulnerable endpoint until a vendor patch is released

Generated by OpenCVE AI on September 18, 2026 at 05:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
Description AVideo (WWBN/AVideo) through 29.0 (commit e01e41ecc) is vulnerable to cross-site request forgery. objects/videoAddNew.json.php disables AVideo's automatic CSRF guard ($global['skipAutoCSRFCheck']) and the untrusted-request check ($global['bypassSameDomainCheck']) merely because 'user' and 'pass' parameters are present in the request; the values are never validated and are read from $_REQUEST, so an attacker can supply them in the query string of a cross-site request. Because User::loginFromRequestIfNotLogged() returns immediately when a session already exists, a victim who is authenticated by cookie satisfies the check while the attacker-supplied credentials are discarded. An attacker who lures an authenticated user with upload rights to visit a crafted page can therefore submit cross-origin requests that modify video records — including ownership transfer (setUsers_id), deletion of user-group access restrictions, can_download, can_share, only_for_paid, video_password, rating, status, creation date, and view count. For a victim with administrator or Permissions::canAdminVideos() rights, any video on the site can be altered, including removing group restrictions from private content. No patched version was available at the time of the advisory.
Title AVideo through 29.0 Broken Access Control via videoAddNew.json.php CSRF Bypass
First Time appeared Wwbn
Wwbn avideo
Weaknesses CWE-352
CPEs cpe:2.3:a:wwbn:avideo:*:*:*:*:*:*:*:*
Vendors & Products Wwbn
Wwbn avideo
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:N'}

cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-17T19:23:41.097Z

Reserved: 2026-09-16T13:47:20.117Z

Link: CVE-2026-92582

cve-icon Vulnrichment

Updated: 2026-09-17T19:15:48.750Z

cve-icon NVD

Status : Deferred

Published: 2026-09-16T22:18:28.600

Modified: 2026-09-22T20:43:58.793

Link: CVE-2026-92582

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T08:00:06Z

Weaknesses
  • CWE-352

    Cross-Site Request Forgery (CSRF)