Wwbn

Avideo

345 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.12%
  • Veröffentlicht 03.09.2026 11:22:13
  • Zuletzt bearbeitet 08.09.2026 20:18:59

AVideo through commit c91b5975d contains a cross-site request forgery vulnerability in plugin/Live/saveLive.php that lacks forbidIfNotPost and forbidIfInvalidToken protections. Attackers can craft malicious image tags to overwrite authenticated strea...

  • EPSS 0.21%
  • Veröffentlicht 03.09.2026 11:22:12
  • Zuletzt bearbeitet 08.09.2026 20:18:59

AVideo through commit c91b5975d contains a cross-site request forgery and path traversal vulnerability in stopLive.php that allows attackers to delete directories by exploiting missing token validation and unsanitized key parameter concatenation. Att...

  • EPSS 0.16%
  • Veröffentlicht 03.09.2026 11:22:11
  • Zuletzt bearbeitet 08.09.2026 20:18:59

AVideo through commit c91b5975d contains a reflected cross-site scripting vulnerability in videoEmbeded.php that echoes the link parameter inside an HTML comment with zero escaping. Attackers can close the comment with --> and inject arbitrary JavaSc...

  • EPSS 0.17%
  • Veröffentlicht 03.09.2026 11:22:11
  • Zuletzt bearbeitet 08.09.2026 20:18:59

AVideo through commit c91b5975d contains a reflected cross-site scripting vulnerability in userLogin.php where the cancelUri parameter is echoed in an href attribute after isSafeRedirectURL checks protocol only, not HTML characters. Unauthenticated a...

  • EPSS 0.21%
  • Veröffentlicht 03.09.2026 11:22:10
  • Zuletzt bearbeitet 08.09.2026 20:18:59

WWBN AVideo contains a broken access control vulnerability in the unauthenticated feed/index.php endpoint that disables per-video visibility checks when a program_id parameter is supplied. Attackers can enumerate playlist identifiers and retrieve unl...

  • EPSS 0.27%
  • Veröffentlicht 03.09.2026 11:22:09
  • Zuletzt bearbeitet 08.09.2026 20:18:59

WWBN AVideo contains a SQL injection vulnerability in the sort column parameter of the get.json.php endpoint with APIName=channels that allows unauthenticated attackers to order results by arbitrary database columns including users.password and users...

  • EPSS 0.21%
  • Veröffentlicht 03.09.2026 11:22:09
  • Zuletzt bearbeitet 08.09.2026 20:18:59

WWBN AVideo fails to properly validate access controls on the public channel page, allowing unauthenticated visitors to view unlisted and group-restricted videos through hardcoded visibility flags and an undefined property. Attackers can access the c...

  • EPSS 0.35%
  • Veröffentlicht 03.09.2026 11:22:08
  • Zuletzt bearbeitet 08.09.2026 20:18:59

WWBN AVideo contains an authentication failure vulnerability where the video_id_hash credential is a non-expiring, non-revocable bearer token that grants full administrator session access to the video owner's account. Attackers who obtain a video_id_...

  • EPSS 0.14%
  • Veröffentlicht 01.09.2026 22:25:35
  • Zuletzt bearbeitet 08.09.2026 20:18:59

WWBN AVideo through commit 9c39d8c8 contains a cross-site request forgery vulnerability in the get_domain() and isSameDomain() functions that fail to properly validate referer origins. Attackers can forge requests from sibling subdomains or unparseab...

  • EPSS 0.27%
  • Veröffentlicht 01.09.2026 22:25:35
  • Zuletzt bearbeitet 08.09.2026 20:18:59

WWBN AVideo through commit 9c39d8c8 contains an incomplete authentication bypass in encryptPass.json.php that allows unauthenticated attackers to compute valid HMAC tokens using the public site URL and current time. Attackers can forge authentication...