Junglewise Threat Intelligence

CVE-2026-57944: AVideo cross-site request forgery in Gallery plugin

CVE-2026-57944 · Severity: medium · CVSS 5.4 · Published 2026-08-22

Technologies: WWBN AVideo. Vendors: WWBN.

Executive brief

AVideo is a video hosting and streaming platform. The Gallery plugin—which manages the site's front page—has a cross-site request forgery (CSRF) flaw that allows attackers to modify what content appears on the homepage without the administrator's knowledge. An attacker can trick an admin into visiting a malicious page, then use that visit to promote their own videos to the front page, delete sections, or otherwise deface the curated gallery layout.

Technical details

The vulnerability is a cross-site request forgery (CWE-352) in the plugin/Gallery/channelToGallery.json.php endpoint. The flaw occurs because the endpoint accepts GET requests, reads user input from $_REQUEST parameters (users_id and add), and performs configuration writes (via Gallery::setAddChannelToGallery() and AVideoPlugin::setObjectData()) with only a role check (User::isAdmin()) and no CSRF token validation. The automatic CSRF guard in include_config.php only activates for POST requests. An attacker can craft a cross-site GET request (delivered via <img> tag or link) that, when loaded by an admin, carries the admin's SameSite=None session cookie and rewrites the Gallery configuration. An attacker with a registered channel can promote it to the homepage (Order=1) or delete gallery sections (add=0). The sibling endpoint saveSort.json.php in the same plugin correctly implements token validation (isGlobalTokenValid()), establishing the fix precedent. Patches are not yet publicly available.

Affected products

  • WWBN AVideo through commit 9c39d8c8

Timeline

  • 2026-08-22: disclosed: Public advisory published by GitHub Security Lab
  • 2026-08-07: advisory: GitHub Security Advisory GHSA-8qq4-h7xj-p2c4 published

References

Related threats