5.4
CVE-2026-92579
- EPSS 0.16%
- Veröffentlicht 16.09.2026 21:46:47
- Zuletzt bearbeitet 22.09.2026 20:43:58
- Erkennungen
AVideo through 29.0 Broken Access Control via CSRF Exemption Basename Collision
AVideo <= 29.0 - Cross-Site Request Forgery
In AVideo through 29.0, the autoCSRFGuard() function maintains a hardcoded allowlist of exempt basenames tested without directory context, allowing plugin files matching core filenames to inherit CSRF exemptions. The LoginWordPress plugin file login.json.php inherits an exemption and unconditionally logs out authenticated users on cross-site POST requests before validating credentials.
Mögliche Gegenmaßnahme
aVideo: No known patch available. Please review the vulnerability's details in depth and employ mitigations based on your organization's risk tolerance. It may be best to uninstall the affected software and find a replacement.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerWWBN
≫
Produkt
AVideo
Default Statusunaffected
Version <=
29.0
Version
0
Status
affected
VulnDex Vulnerability Enrichment
Weitere Schwachstelleninformationen
SystemWordPress Plugin
≫
Produkt
aVideo
Version
*-29.0
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.16% | 0.053 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| disclosure@vulncheck.com | 5.3 | 0 | 0 |
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
|
| disclosure@vulncheck.com | 5.4 | 2.8 | 2.5 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L
|
CWE-289 Authentication Bypass by Alternate Name
The product performs authentication based on the name of a resource being accessed, or the name of the actor performing the access, but it does not properly check all possible names for that resource or actor.
https://github.com/WWBN/AVideo/security/advisories/GHSA-3hg6-6x7m-5xr8
https://www.vulncheck.com/advisories/avideo-through-29.0-broken-access-control-via-csrf-exemption-basename-collision
https://www.wordfence.com/threat-intel/vulnerabilities/id/5e8b7b1d-66de-4707-9db1-b9aa87e88f98