Executive brief
WWBN AVideo is a video hosting and streaming platform. When the Live plugin is enabled, a flaw in the notification system allows an unauthenticated attacker who knows an administrator's live stream key to send arbitrary in-app notification messages to that administrator. This could be used for social engineering, malicious notifications, or service disruption.
Technical details
The vulnerability is a missing authentication and authorization check (CWE-306, CWE-862) in plugin/Live/socketMessageLiveOwner.json.php. The script accepts `key` and `msg` parameters from $_REQUEST and resolves the stream owner via LiveTransmition::keyExists, then verifies the stream owner (not the caller) is an administrator. However, it performs no User::isLogged() check and enforces no CSRF token, allowing unauthenticated remote attackers to call sendSocketSuccessMessageToUsers_id. An attacker who knows a valid administrator live stream key can deliver arbitrary socket notification messages to that administrator. The vulnerability requires only network access and knowledge of a valid stream key; no user interaction or privileges are required. At the time of publication, this issue was unpatched.
Affected products
- WWBN AVideo commit c3edcc274c389816d434acadac07ee78eaf330c1 and earlier (with Live plugin enabled)
Timeline
- 2026-09-12: disclosed
- other: unpatched at time of publication