Junglewise Threat Intelligence

CVE-2026-34611: WWBN AVideo CSRF in emailAllUsers.json.php

CVE-2026-34611 · Severity: medium · CVSS 6.5 · Published 2026-03-31

Technologies: wwbn/avideo (Packagist), WWBN AVideo. Vendors: Packagist, WWBN.

Executive brief

WWBN AVideo is an open-source video sharing platform. A security flaw allows an attacker to trick a logged-in administrator into unknowingly sending mass emails to every registered user on the platform. These emails appear to come from the legitimate site, making them highly effective for phishing or spreading malware, which can severely damage the organization's reputation and compromise user accounts.

Technical details

A Cross-Site Request Forgery (CSRF) vulnerability exists in the `objects/emailAllUsers.json.php` endpoint of WWBN AVideo versions 26.0 and earlier. The endpoint lacks CSRF token validation and relies on session cookies that are configured with `SameSite=None`, allowing cross-origin POST requests to succeed if an administrator is authenticated. By luring an admin to a malicious site, an attacker can trigger a request that sends arbitrary HTML content to all registered users via the platform's configured SMTP server. This bypasses standard email protections like SPF and DKIM because the emails originate from the legitimate server. As of the advisory date, no official patch is available; administrators are advised to implement manual CSRF token checks in the affected PHP file.

Affected products

  • WWBN AVideo <= 26.0

Timeline

  • 2026-03-30: advisory: GitHub Security Advisory published
  • 2026-03-31: disclosed: NVD publication date

References

Related threats