CVE-2026-34611: 
PHP vulnerability analysis and mitigation

Overview

CVE-2026-34611 is a Cross-Site Request Forgery (CSRF) vulnerability in WWBN AVideo, an open source video platform, affecting versions 26.0 and prior. The flaw exists in the objects/emailAllUsers.json.php endpoint, which allows an attacker to trick an authenticated administrator into sending arbitrary HTML emails to every registered user on the platform. It was published on March 31, 2026, with the GitHub Advisory (GHSA-c4xj-x7p8-3x7q) released on April 1, 2026. The vulnerability carries a CVSS v3.1 base score of 6.5 (Medium) (GitHub Advisory, AVideo Advisory).

Technical details

The root cause is a missing CSRF token validation on the objects/emailAllUsers.json.php endpoint (CWE-352). While the endpoint checks for an active admin session at line 10 (if (!User::isAdmin())), it never calls isGlobalTokenValid() or any equivalent CSRF check. Compounding the issue, AVideo configures session cookies with SameSite=None, which causes browsers to automatically include the admin's session cookie in cross-origin POST requests. The message body is taken directly from $_POST['message'] (line 41) and rendered as raw HTML via $mail->msgHTML() (line 48); when no specific email address is provided, the endpoint defaults to User::getAllUsers(), targeting every registered user without requiring the attacker to know any email addresses. Because the endpoint bypasses the ObjectYPT::save() method where Referer/Origin validation is implemented, no secondary protection is triggered (AVideo Advisory).

Impact

Successful exploitation allows an unauthenticated attacker (who can lure an admin to a malicious page) to send attacker-controlled HTML emails to every registered user on the AVideo platform. Because the emails are dispatched through the platform's configured SMTP server, they originate from the legitimate platform email address and pass SPF, DKIM, and DMARC authentication checks, making them indistinguishable from genuine platform communications. This enables mass phishing campaigns, credential harvesting via attacker-controlled login pages, malware distribution through HTML email payloads, and significant reputational damage to the platform operator — all without requiring knowledge of any user email addresses (AVideo Advisory, GitHub Advisory).

Exploitability

A proof-of-concept (PoC) exploit is publicly available in the GitHub Security Advisory, including a complete auto-submitting HTML form and a curl command that can be executed against a live AVideo instance (AVideo Advisory). The attack requires only that an authenticated administrator visits an attacker-controlled page — a single user interaction. There is no evidence of in-the-wild exploitation at this time, and no threat actor attribution has been reported. The EPSS score is approximately 0.014% (1st percentile), indicating a currently low probability of active exploitation (GitHub Advisory). The vulnerability is not listed in the CISA KEV catalog.

Exploitation steps

  1. Reconnaissance: Identify publicly accessible WWBN AVideo instances running version 26.0 or earlier. Confirm the target is reachable and has registered users.
  2. Craft malicious HTML page: Create an HTML page on an attacker-controlled domain containing a hidden form that auto-submits a POST request to https://target-avideo-instance.com/objects/emailAllUsers.json.php with attacker-defined subject and message (HTML) parameters.
  3. Embed phishing content: Populate the message field with convincing HTML content (e.g., an account verification notice with a link to an attacker-controlled credential-harvesting page).
  4. Lure the administrator: Send the link to the malicious page to an AVideo administrator via email, social engineering, or other means, inducing them to visit it while authenticated to the AVideo instance.
  5. CSRF triggers automatically: When the admin's browser loads the attacker's page, the auto-submit script fires a cross-origin POST request to the AVideo endpoint. Because SameSite=None is set on session cookies, the admin's PHPSESSID cookie is included automatically.
  6. Mass email delivery: The endpoint passes the admin session check, accepts the POST body, and sends the attacker-crafted HTML email to all registered users via the platform's SMTP server, with the email appearing to originate from the legitimate platform address and passing SPF/DKIM/DMARC validation (AVideo Advisory).

Indicators of compromise

  • Network: Unexpected cross-origin POST requests to /objects/emailAllUsers.json.php from browser sessions; outbound SMTP traffic volume spike from the AVideo server following an admin login event.
  • Logs: Web server access logs showing POST requests to objects/emailAllUsers.json.php with a Referer header pointing to an external or unknown domain; SMTP server logs showing a sudden bulk email send event to all registered users.
  • Application: AVideo application logs recording a mass email dispatch not initiated through the normal admin UI workflow; email delivery records showing all users received an unsolicited message from the platform's SMTP address.
  • User Reports: Registered users reporting receipt of unexpected or suspicious emails appearing to originate from the platform's legitimate address (AVideo Advisory).

Mitigation and workarounds

No official patched version of AVideo was available at the time of advisory publication (all versions ≤ 26.0 are affected). The recommended fix is to add CSRF token validation immediately after the admin check in objects/emailAllUsers.json.php using isGlobalTokenValid(). As interim mitigations, administrators should reconfigure session cookies to use SameSite=Strict or SameSite=Lax instead of SameSite=None, implement an approval workflow or secondary confirmation for bulk email operations, and educate administrators about the risk of visiting untrusted websites while authenticated. Monitor the AVideo GitHub repository for patch releases (AVideo Advisory, GitHub Advisory).

Community reactions

The vulnerability was discovered and reported by aisafe.io (finder: aisafe-bot; reporter: adrgs) and published by the AVideo maintainer DanielnetoDotCom on March 30, 2026. The advisory was noted in automated CVE tracking feeds and Bluesky CVE notification accounts shortly after publication. No significant broader media coverage or notable researcher commentary beyond the advisory itself has been identified (AVideo Advisory).

Additional resources


Source: This report was generated using AI

Related PHP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-55224HIGH8.7
  • PHP logoPHP
  • mineadmin/mineadmin
NoYesSep 30, 2026
CVE-2026-103111HIGH7.6
  • MariaDB Server logoMariaDB Server
  • mariadb11.8-server
NoYesSep 30, 2026
GHSA-3q6v-r5mr-hxv8HIGH7.5
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
GHSA-97jj-33gv-5xf9MEDIUM6.1
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
CVE-2026-104181MEDIUM5.4
  • PHP logoPHP
  • filament/filament
NoYesOct 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management