The WWBN AVideo platform has critical security vulnerabilities in versions 29.0 and below that allow arbitrary file deletion and unauthorized access to API endpoints.
Claims
The WWBN AVideo platform has critical security vulnerabilities in versions 29.0 and below that allow arbitrary file deletion and unauthorized access to API endpoints.
Parent: CybersecurityEntity: WWBN AVideoImpact: negativeDate: Apr 22, 2026Target: The security of the WWBN AVideo platform
Source posts
๐จ EUVD-2026-24533
๐ Score: 7.1/10 (CVSS v3.1)
๐ฆ Product: AVideo
๐ข Vendor: WWBN
๐
Updated: 2026-04-21
๐ WWBN AVideo is an open source video platform. In versions 29.0 and below, the CORS origin validation fix in commit `986e64aad` is incomplete. Two separate code paths still reflect arbitrary `Origin` headers with credentials allowed for all `/api/*` endpoints: (1...
๐ https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-24533
#cybersecurity #infosec #euvd #cve #vulnerability
0 boosts ยท 0 favs ยท 0 replies ยท Apr 22, 2026
#cybersecurity#infosec#euvd#cve#vulnerability
๐จ EUVD-2026-24535
๐ Score: 8.1/10 (CVSS v3.1)
๐ฆ Product: AVideo
๐ข Vendor: WWBN
๐
Updated: 2026-04-21
๐ WWBN AVideo is an open source video platform. In versions 29.0 and below, the incomplete fix for AVideo's CloneSite `deleteDump` parameter does not apply path traversal filtering, allowing `unlink()` of arbitrary files via `../../` sequences in the GET parameter...
๐ https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-24535
#cybersecurity #infosec #euvd #cve #vulnerability
0 boosts ยท 0 favs ยท 0 replies ยท Apr 22, 2026
#cybersecurity#infosec#euvd#cve#vulnerability