Description
WWBN AVideo through commit e01e41ecc (no patched version available) contains a broken access control flaw in objects/userVerifyEmail.php. The script disables the login requirement ($global['ignoreUserMustBeLoggedIn'] = 1), takes users_id directly from the query string, and calls User::sendVerificationLink() with no session requirement, no CSRF/global token, no relationship check between caller and target, and no enforceRateLimit() call. The only intended throttle is keyed to the caller's own session, so cookie-less requests are never limited. An unauthenticated remote attacker can therefore cause an arbitrary number of verification emails to be sent to any account ID, and can enumerate accounts and their verification status from the three distinct JSON responses ("Verification Sent", "Already verified", "Unknown error"). In addition, createVerificationCode() invokes $user->setRecoverPass() and saves the user, so each anonymous request writes a live password-recovery token onto the targeted account; that token is embedded in base64 in the verification link emailed to the account owner and is accepted by objects/userRecoverPassSave.json.php as the credential for setting a new password.
Published: 2026-09-17
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized password reset via verification link
Action: Assess Impact
AI Analysis

Impact

A broken access control flaw in WWBN AVideo’s userVerifyEmail.php disables the login requirement, accepts a user ID directly from the query string, and calls User::sendVerificationLink() without session validation, CSRF protection, or relationship checks. The script also does not enforce rate limiting beyond the caller’s own session, allowing an unauthenticated attacker to trigger an arbitrary number of verification emails. Each request creates a live password‑recovery token stored in the account, embedded in the emailed link, and accepted by a separate recovery handler to set a new password.

Affected Systems

The vulnerability exists in WWBN AVideo, commit e01e41ecc. No patched version is currently available, and the advisory does not specify a fixed release or affected version range.

Risk and Exploitability

The CVSS score of 6.9 indicates a moderate impact. EPSS is not available, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is an unauthenticated HTTP request to objects/userVerifyEmail.php with a specified user_id. Successful exploitation enables account enumeration through distinct JSON responses, mass email spam of verification links, and the creation of valid password‑reset tokens that can be used by the attacker to obtain full control of the targeted account.

Generated by OpenCVE AI on September 17, 2026 at 21:49 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Require authentication before allowing access to userVerifyEmail.php and verify that the caller is the target user.
  • Enforce CSRF protection or a global token for all state‑changing requests to this endpoint.
  • Implement a global rate limiting policy that limits verification link requests per user or IP address instead of per session.
  • Disable or secure the password‑reset token generation logic so that anonymous requests do not create valid tokens.
  • Check for and apply any future patch or update released by WWBN once available.

Generated by OpenCVE AI on September 17, 2026 at 21:49 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 11:30:00 +0000

Type Values Removed Values Added
Description WWBN AVideo through commit e01e41ecc (no patched version available) contains a broken access control flaw in objects/userVerifyEmail.php. The script disables the login requirement ($global['ignoreUserMustBeLoggedIn'] = 1), takes users_id directly from the query string, and calls User::sendVerificationLink() with no session requirement, no CSRF/global token, no relationship check between caller and target, and no enforceRateLimit() call. The only intended throttle is keyed to the caller's own session, so cookie-less requests are never limited. An unauthenticated remote attacker can therefore cause an arbitrary number of verification emails to be sent to any account ID, and can enumerate accounts and their verification status from the three distinct JSON responses ("Verification Sent", "Already verified", "Unknown error"). In addition, createVerificationCode() invokes $user->setRecoverPass() and saves the user, so each anonymous request writes a live password-recovery token onto the targeted account; that token is embedded in base64 in the verification link emailed to the account owner and is accepted by objects/userRecoverPassSave.json.php as the credential for setting a new password.
Title WWBN AVideo userVerifyEmail.php Unauthenticated Access Control
First Time appeared Wwbn
Wwbn avideo
Weaknesses CWE-770
CPEs cpe:2.3:a:wwbn:avideo:*:*:*:*:*:*:*:*
Vendors & Products Wwbn
Wwbn avideo
References
Metrics cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-17T14:26:52.365Z

Reserved: 2026-09-17T11:07:29.772Z

Link: CVE-2026-92915

cve-icon Vulnrichment

Updated: 2026-09-17T14:26:46.547Z

cve-icon NVD

Status : Deferred

Published: 2026-09-17T12:18:30.573

Modified: 2026-09-22T20:43:58.793

Link: CVE-2026-92915

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T22:00:16Z

Weaknesses
  • CWE-770

    Allocation of Resources Without Limits or Throttling