Executive brief
AVideo is a video hosting and streaming platform. The Gallery plugin—which manages the site's front page—has a cross-site request forgery (CSRF) flaw that allows attackers to modify what content appears on the homepage without the administrator's knowledge. An attacker can trick an admin into visiting a malicious page, then use that visit to promote their own videos to the front page, delete sections, or otherwise deface the curated gallery layout.
Technical details
The vulnerability is a cross-site request forgery (CWE-352) in the plugin/Gallery/channelToGallery.json.php endpoint. The flaw occurs because the endpoint accepts GET requests, reads user input from $_REQUEST parameters (users_id and add), and performs configuration writes (via Gallery::setAddChannelToGallery() and AVideoPlugin::setObjectData()) with only a role check (User::isAdmin()) and no CSRF token validation. The automatic CSRF guard in include_config.php only activates for POST requests. An attacker can craft a cross-site GET request (delivered via <img> tag or link) that, when loaded by an admin, carries the admin's SameSite=None session cookie and rewrites the Gallery configuration. An attacker with a registered channel can promote it to the homepage (Order=1) or delete gallery sections (add=0). The sibling endpoint saveSort.json.php in the same plugin correctly implements token validation (isGlobalTokenValid()), establishing the fix precedent. Patches are not yet publicly available.
Affected products
- WWBN AVideo through commit 9c39d8c8
Timeline
- 2026-08-22: disclosed: Public advisory published by GitHub Security Lab
- 2026-08-07: advisory: GitHub Security Advisory GHSA-8qq4-h7xj-p2c4 published