Executive brief
WWBN AVideo is a video hosting platform used to manage and share multimedia content. An attacker can exploit a cross-site request forgery vulnerability to trick an authenticated administrator into sending emails from the site's official address to arbitrary recipients with attacker-controlled content, enabling phishing attacks and brand impersonation while bypassing email authentication checks.
Technical details
The vulnerability is a cross-site request forgery (CWE-352) in objects/sendEmail.json.php that affects authenticated administrators. The sendEmail.json.php endpoint is whitelisted in the CSRF bypass list within autoCSRFGuard(), exempting it from origin checks, and administrators automatically bypass captcha validation. An attacker can craft a malicious webpage containing an auto-submitting form that, when visited by a logged-in admin, sends emails from the site's official contact address to arbitrary recipients with attacker-chosen subject and body. Since the From address is the site's legitimate domain, the emails pass SPF/DKIM/DMARC validation, enabling credible phishing and brand impersonation. The request requires the admin to visit the malicious page while logged in but no additional interaction or preflight checks are needed due to simple cross-origin form submission mechanics. A patch has been suggested but not yet released; legitimate callers (same-origin contact forms and share dialogs) would not be affected by removing the endpoint from the bypass list.
Affected products
- WWBN AVideo current (e01e41ecc) and earlier
Timeline
- 2026-08-14: disclosed: GitHub Security Advisory GHSA-7h9v-f3gg-r3mq published
- 2026-08-30: advisory: CVE-2026-82647 published on NVD
- 2026-08-30: other: VulnCheck advisory published