MEDIUM 5.1 NVD
CVE-2026-81733
WWBN AVideo through 30.0 (and master up to commit 4cb576e) contains a cross-site request forgery vulnerability in plugin/Live/myLiveControls.save.json.php. The
WWBN AVideo through 30.0 (and master up to commit 4cb576e) contains a cross-site request forgery vulnerability in plugin/Live/myLiveControls.save.json.php. The endpoint only checks that a user is logged in and processes customUrl, customMessage, and autoRedirect parameters from $_REQUEST via a GET request without enforcing a CSRF token or origin check. An attacker who lures a logged-in streamer to a malicious page can silently change the live-channel viewer-redirect settings (persisted in users.externalOptions), causing viewers to be redirected to a phishing site or shown a spoofed message.
References
- https://github.com/WWBN/AVideo/security/advisories/GHSA-wpr3-456q-6vgc
- https://www.vulncheck.com/advisories/wwbn-avideo-through-30.0-csrf-via-mylivecontrols-save
- https://github.com/WWBN/AVideo/security/advisories/GHSA-wpr3-456q-6vgc
This medium severity vulnerability with a CVSS score of 5.1 was published on 2026-08-28 via NVD.
vulnfeed aggregates 11493 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.