Executive brief
WWBN AVideo is an open-source platform used for hosting and managing video content. A security flaw in the platform's login control settings allows an attacker to silently disable a user's Two-Factor Authentication (2FA) if the user visits a malicious website while logged into their AVideo account. This effectively removes a critical layer of security, making the account vulnerable to takeover through simple password theft or credential stuffing.
Technical details
A Cross-Site Request Forgery (CSRF) vulnerability exists in the `plugin/LoginControl/set.json.php` endpoint of WWBN AVideo. The endpoint lacks CSRF protection mechanisms such as `forbidIfIsUntrustedRequest()` calls, token validation (`isTokenValid`), or SameSite=Strict cookie enforcement. An attacker can host a malicious page that auto-submits a POST request to this endpoint with `type=set2FA` and `value=false`. If a logged-in user visits the attacker's site, their browser will include their session cookies in the request, causing the server to disable 2FA for their account without their knowledge or consent. This vulnerability is particularly severe as it lacks a re-authentication step (password or 2FA code prompt) for disabling security-sensitive features. As of the advisory, no patch is explicitly mentioned, though the root cause is the omission of standard AVideo CSRF helpers in this specific file.
Affected products
- WWBN AVideo <= 29.0
Timeline
- 2026-05-11: advisory: GitHub security advisory published by researcher
- 2026-05-29: disclosed: CVE published to NVD