← Volver al buscador de CVEs

CVE-2026-34611

AVideo

Descripción

WWBN AVideo is an open source video platform. In versions 26.0 and prior, the AVideo endpoint objects/emailAllUsers.json.php allows administrators to send HTML emails to every registered user on the platform. While the endpoint verifies admin session status, it does not validate a CSRF token. Because AVideo sets SameSite=None on session cookies, a cross-origin POST request from an attacker-controlled page will include the admin-s session cookie automatically. An attacker who lures an admin to a malicious page can send an arbitrary HTML email to every user on the platform, appearing to originate from the instance-s legitimate SMTP address. At time of publication, there are no publicly available patches.

CVSS 6.5EPSS 0.157%Riesgo 0.66
Ver fuente
Publicación
2026-03-31 21:16:31
Versiones afectadas
<=26.0
Tipo
Core software
Última modificación
2026-07-24 20:10:00
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N