Executive brief
WWBN AVideo is a video hosting and management platform. An attacker can trick an administrator into visiting a malicious webpage that permanently publishes embargoed (scheduled-release) videos without the administrator's knowledge or consent. This bypasses content embargo controls and exposes unreleased or restricted content to the public.
Technical details
The vulnerability is a cross-site request forgery (CVSS-352) in the plugin/Scheduler/releaseVideoNow.json.php endpoint. The endpoint accepts GET requests, reads the attacker-controlled videos_id parameter from $_REQUEST, and makes a database mutation (publishing a video) without validating request authenticity (no forbidIfIsUntrustedRequest, isTokenValid, or isGlobalTokenValid calls). The only authorization check is Video::canEdit(), which returns true unconditionally for administrators, meaning any GET request carrying an administrator's session cookie can publish any video on the platform. The automatic CSRF guard in include_config.php only protects POST requests, leaving GET-reachable mutations unprotected. An attacker can deliver the malicious GET via an img tag or link on a website; on HTTPS deployments, the session cookie is sent due to SameSite=None cookie policy. No patch is currently available.
Affected products
- WWBN AVideo through commit 9c39d8c8b4c1f75540788d6b391740852ceb0732
Timeline
- 2026-08-07: disclosed
- 2026-08-22: advisory