Executive brief
AVideo, a video sharing platform, contains a security flaw that allows an attacker to change a user's profile picture without their permission. By tricking a logged-in user into visiting a malicious website, the attacker can overwrite the user's profile photo with any image or data. This can be used to deface profiles, impersonate others, or cause performance issues by repeatedly forcing the system to clear its internal cache.
Technical details
A Cross-Site Request Forgery (CSRF) vulnerability exists in 'objects/userSavePhoto.php' (and 'objects/userSaveBackground.php') because these legacy endpoints are excluded from the global 'autoCSRFGuard' due to a suffix-based filtering mechanism that only protects files ending in '.json.php'. The application also defaults to 'SameSite=None; Secure' cookies on HTTPS, allowing cross-origin POST requests to include session cookies. An attacker can exploit this by hosting a malicious form that sends a base64-encoded payload to the vulnerable endpoint. Since the endpoint lacks MIME validation and size limits, it can be used for profile defacement, disk exhaustion, and sustained application-wide cache invalidation via the 'clearCache(true)' call.
Affected products
- WWBN AVideo (formerly YouPHPTube) <= 29.0
Timeline
- 2026-04-25: disclosed
- 2026-05-05: advisory