Impact
A broken access control flaw in WWBN AVideo’s userVerifyEmail.php disables the login requirement, accepts a user ID directly from the query string, and calls User::sendVerificationLink() without session validation, CSRF protection, or relationship checks. The script also does not enforce rate limiting beyond the caller’s own session, allowing an unauthenticated attacker to trigger an arbitrary number of verification emails. Each request creates a live password‑recovery token stored in the account, embedded in the emailed link, and accepted by a separate recovery handler to set a new password.
Affected Systems
The vulnerability exists in WWBN AVideo, commit e01e41ecc. No patched version is currently available, and the advisory does not specify a fixed release or affected version range.
Risk and Exploitability
The CVSS score of 6.9 indicates a moderate impact. EPSS is not available, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is an unauthenticated HTTP request to objects/userVerifyEmail.php with a specified user_id. Successful exploitation enables account enumeration through distinct JSON responses, mass email spam of verification links, and the creation of valid password‑reset tokens that can be used by the attacker to obtain full control of the targeted account.
OpenCVE Enrichment