Junglewise Threat Intelligence

CVE-2026-89245: WWBN AVideo CSRF in playlistRemove.php

CVE-2026-89245 · Severity: medium · CVSS 6.5 · Published 2026-09-11

Technologies: WWBN AVideo. Vendors: WWBN.

Executive brief

WWBN AVideo is a video hosting and streaming platform. A cross-site request forgery (CSRF) vulnerability in the playlist management feature allows attackers to trick logged-in users into deleting their playlists by visiting a malicious webpage. The attacker can delete any playlist belonging to the victim without their knowledge or consent, resulting in loss of user-curated content such as watch-later lists or custom video collections.

Technical details

The playlistRemove.php endpoint fails to implement CSRF protection because the filename does not follow the .json.php naming convention that triggers automatic CSRF guards in the application's include_config.php. The vulnerable code performs state-changing operations (playlist deletion) after only checking user login status and ownership, without calling forbidIfIsUntrustedRequest() or invoking autoCSRFGuard(). An attacker can craft a malicious HTML form that submits a cross-origin POST request to playlistRemove.php; when a logged-in victim visits the attacker's page, their session cookie is automatically sent by the browser (even with SameSite=Lax), causing the playlist deletion to succeed. The fix requires either renaming the file to *.json.php or explicitly calling forbidIfIsUntrustedRequest() after the login check.

Affected products

  • WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1

Timeline

  • 2026-08-27: disclosed
  • 2026-09-11: advisory

References

Related threats