Wwbn

Avideo

345 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.32%
  • Veröffentlicht 08.09.2026 15:13:59
  • Zuletzt bearbeitet 08.09.2026 19:53:13

AVideo through 29.0 contains an authentication bypass vulnerability in plugin/PlayLists/epg.json.php that exposes live-stream keys and private EPG schedules to unauthenticated users. Attackers can request the endpoint with sequential user or playlist...

  • EPSS 0.26%
  • Veröffentlicht 08.09.2026 15:13:58
  • Zuletzt bearbeitet 19.09.2026 15:17:06

AVideo through 29.0 contains an information disclosure vulnerability in restreamsActive.json.php that allows authenticated streamers to enumerate source stream keys and identities of all other streamers' active restreams. The endpoint fails to filter...

  • EPSS 0.31%
  • Veröffentlicht 08.09.2026 15:13:58
  • Zuletzt bearbeitet 10.09.2026 14:17:09

AVideo through 29.0 contains an information disclosure vulnerability in plugin/Live/stats.json.php that allows unauthenticated attackers to retrieve stream keys and m3u8 URLs by accessing the endpoint without authentication. Attackers can enumerate p...

  • EPSS 0.3%
  • Veröffentlicht 08.09.2026 15:13:57
  • Zuletzt bearbeitet 08.09.2026 19:53:13

AVideo through c3edcc274c389816d434acadac07ee78eaf330c1 contains a missing authorization vulnerability in the SocialMediaPublisher plugin's add.json.php endpoint that allows authenticated users to modify other users' OAuth token records. Attackers ca...

  • EPSS 0.27%
  • Veröffentlicht 08.09.2026 15:13:56
  • Zuletzt bearbeitet 08.09.2026 19:53:13

AVideo through c3edcc274c389816d434acadac07ee78eaf330c1 contains an authentication bypass vulnerability in LoginControl::verifyChallenge() that uses loose comparison (==) instead of strict comparison (===) against unset session values. Attackers with...

  • EPSS 0.13%
  • Veröffentlicht 08.09.2026 15:13:56
  • Zuletzt bearbeitet 10.09.2026 16:18:03

AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a cross-site request forgery vulnerability in plugin/YPTWallet/view/saveBalance.php that allows attackers to set arbitrary wallet balances by relying only on session cookies with...

  • EPSS 0.27%
  • Veröffentlicht 08.09.2026 15:13:55
  • Zuletzt bearbeitet 10.09.2026 14:17:09

AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains an authentication bypass vulnerability where sqlDAL caches empty result sets that writeSql never invalidates. Attackers with a valid password can bypass email two-factor authenti...

  • EPSS 0.26%
  • Veröffentlicht 08.09.2026 15:13:54
  • Zuletzt bearbeitet 08.09.2026 19:53:13

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate ownership of live_restreams_id in resendRestreamer.json.php, allowing authenticated users with canStream to access other users' restream destinations. Attackers can...

  • EPSS 0.29%
  • Veröffentlicht 08.09.2026 15:13:54
  • Zuletzt bearbeitet 19.09.2026 15:17:06

AVideo through commit c3edcc274c contains an authorization bypass vulnerability where a session cookie named 'key' with value 'value' overrides the $_REQUEST['key'] parameter in saveLive.php and related endpoints. Attackers can publish to any user's ...

  • EPSS 0.11%
  • Veröffentlicht 08.09.2026 15:13:53
  • Zuletzt bearbeitet 10.09.2026 16:18:03

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 (master) contains a cross-site request forgery vulnerability in the CustomizeUser plugin endpoint plugin/CustomizeUser/swapUser.json.php. The endpoint takes users_id from $_REQUEST a...