Wwbn

Avideo

345 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.26%
  • Veröffentlicht 01.09.2026 22:25:34
  • Zuletzt bearbeitet 08.09.2026 20:18:59

WWBN AVideo through 30.0 contains an information disclosure vulnerability in the MobileManager plugin getConfiguration endpoint that returns sensitive configuration data to unauthenticated visitors. Attackers can send an unauthenticated GET request t...

  • EPSS 0.32%
  • Veröffentlicht 01.09.2026 22:25:33
  • Zuletzt bearbeitet 08.09.2026 20:18:59

WWBN AVideo (current e01e41ecc and earlier) makes three login-time security controls depend solely on the client-supplied User-Agent header. The isAVideoEncoder()/isAVideoMobileApp() checks match HTTP_USER_AGENT against a hardcoded literal ("AVideoEn...

  • EPSS 0.29%
  • Veröffentlicht 01.09.2026 22:25:33
  • Zuletzt bearbeitet 08.09.2026 20:18:59

WWBN AVideo fails to validate password recovery token expiration in userRecoverPassSave.json.php, allowing attackers to use expired tokens to reset account passwords indefinitely. Attackers who obtain a recovery token can use it at any time to change...

  • EPSS 0.36%
  • Veröffentlicht 01.09.2026 22:25:32
  • Zuletzt bearbeitet 08.09.2026 20:18:59

WWBN AVideo contains a path traversal vulnerability in the API get_api_login_code endpoint that allows unauthenticated attackers to delete arbitrary .log files by supplying directory traversal sequences in the code parameter. Attackers can exploit th...

  • EPSS 0.26%
  • Veröffentlicht 01.09.2026 22:25:31
  • Zuletzt bearbeitet 08.09.2026 20:18:59

WWBN AVideo fails to validate trusted proxies before accepting X-Real-IP and X-Forwarded-For headers, allowing attackers to spoof the client address used by enforceRateLimit(). Attackers can rotate the header value per request to bypass login rate li...

  • EPSS 0.17%
  • Veröffentlicht 01.09.2026 22:25:31
  • Zuletzt bearbeitet 08.09.2026 20:18:59

AVideo Live_schedule::setTitle() and setDescription() store POST input without sanitization, allowing users with streaming permission to inject malicious scripts. Unauthenticated attackers can access remindMe.php to execute stored XSS payloads in vic...

  • EPSS 0.28%
  • Veröffentlicht 01.09.2026 22:25:30
  • Zuletzt bearbeitet 08.09.2026 20:18:59

AVideo through version 29.0 contains an unauthenticated SQL injection vulnerability in the User_Location plugin's regions.json.php and cities.json.php endpoints. The country and region GET parameters are passed directly into SQL queries without escap...

  • EPSS 0.35%
  • Veröffentlicht 01.09.2026 11:33:53
  • Zuletzt bearbeitet 08.09.2026 20:18:59

AVideo contains a missing authentication vulnerability in plugin/Live/on_publish.php that allows unauthenticated attackers to mark arbitrary scheduled broadcasts as failed by sending crafted POST requests with schedule identifiers. Attackers can expl...

  • EPSS 0.16%
  • Veröffentlicht 01.09.2026 11:33:52
  • Zuletzt bearbeitet 08.09.2026 20:18:59

AVideo contains a cross-site request forgery vulnerability in plugin/API/set.json.php that allows attackers to perform state-changing actions by crafting GET requests that bypass CSRF protection. Attackers can navigate a victim's browser to a malicio...

  • EPSS 0.2%
  • Veröffentlicht 30.08.2026 14:33:31
  • Zuletzt bearbeitet 02.09.2026 16:17:26

WWBN AVideo contains a server-side request forgery filter bypass vulnerability in the isSSRFSafeURL function that fails to normalize NAT64 addresses written in hexadecimal form. Attackers can bypass SSRF protections by supplying hex-encoded NAT64 add...