CVE-2026-34613: 
PHP vulnerability analysis and mitigation

Overview

CVE-2026-34613 is a Cross-Site Request Forgery (CSRF) vulnerability in WWBN AVideo, an open source video platform, affecting versions 26.0 and prior. The flaw exists in the objects/pluginSwitch.json.php endpoint, which allows administrators to enable or disable plugins without validating a CSRF token. Discovered by aisafe.io and published on March 30, 2026, the vulnerability carries a CVSS v3.1 base score of 6.5 (Medium/Moderate) (GitHub Advisory, Github Advisory DB). At the time of initial publication, no patched version was available, though patch commits have since been referenced in the advisory (Github Advisory DB).

Technical details

The root cause is CWE-352 (Cross-Site Request Forgery): the objects/pluginSwitch.json.php endpoint verifies only that the requester has an active admin session, but performs no CSRF token validation. Compounding the issue, the plugins database table is explicitly listed in ignoreTableSecurityCheck() within objects/Object.php:529, which bypasses the ORM-level Referer/Origin domain validation that normally serves as a secondary CSRF defense in ObjectYPT::save(). Additionally, AVideo session cookies are configured with SameSite=None, ensuring cross-origin requests carry the admin session cookie. Plugin UUIDs — required to target specific plugins — are hardcoded constants exposed in frontend JavaScript source code, making them trivially discoverable by any attacker (GitHub Advisory).

Vulnerable code snippet:

// objects/pluginSwitch.json.php
if (!User::isAdmin()) { die('{"error": "Must be admin"}'); }
$obj = new Plugin(0);
$obj->loadFromUUID($_POST['uuid']);
$obj->setStatus($_POST['status']);
$obj->save();

Impact

Successful exploitation allows an unauthenticated attacker to silently disable any installed AVideo plugin by tricking an authenticated administrator into visiting a malicious page. The most severe consequence is disabling the LoginControl plugin, which removes two-factor authentication and brute force protection for all users, dramatically lowering the barrier for account takeover. Subscription and payment enforcement plugins (PayPal, Stripe) can also be disabled, granting unauthorized access to paid content, while disabling access control plugins exposes private or restricted videos to the public. The attack leaves no visible indication to the administrator, making detection difficult without log analysis (GitHub Advisory).

Exploitability

A proof-of-concept (PoC) exploit is publicly available in the GitHub Security Advisory, including a complete HTML form payload and curl commands with specific plugin UUIDs and parameters (GitHub Advisory). The EPSS score is approximately 0.014% (1st percentile), indicating a low current probability of active exploitation. There is no evidence of in-the-wild exploitation at this time, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported.

Exploitation steps

  1. Reconnaissance: Identify a target AVideo instance (version ≤ 26.0) and confirm it is internet-accessible. Extract plugin UUIDs from the frontend JavaScript source:
curl -s "https://your-avideo-instance.com/" | grep -oP '[a-f0-9]{8}-[a-f0-9]{4}-[a-f0-9]{4}-[a-f0-9]{4}-[a-f0-9]{12}'

Alternatively, use known hardcoded UUIDs (e.g., LoginControl: LoginControl-5ee8405eaaa16, Gallery: a06505bf-3570-4b1f-977a-fd0e5cab205d).

  1. Craft malicious page: Host an HTML page on an attacker-controlled domain containing auto-submitting forms targeting the vulnerable endpoint:
<form id="disable1" action="https://target-avideo.com/objects/pluginSwitch.json.php" method="POST">
  <input type="hidden" name="uuid" value="LoginControl-5ee8405eaaa16">
  <input type="hidden" name="status" value="inactive">
</form>
<script>document.getElementById('disable1').submit();</script>
  1. Deliver the link: Lure an authenticated AVideo administrator to the malicious page via phishing email, social engineering, or embedding in a comment/message on the platform.

  2. CSRF executes: When the admin visits the page, their browser automatically submits the cross-origin POST request to pluginSwitch.json.php, carrying the PHPSESSID cookie (sent due to SameSite=None). The endpoint validates only admin session status and processes the request, disabling the targeted plugin.

  3. Verify impact: Confirm the plugin is disabled (e.g., 2FA is no longer enforced for logins), then proceed with follow-on attacks such as credential stuffing or accessing restricted content (GitHub Advisory).

Indicators of compromise

  • Network: Unexpected cross-origin POST requests to /objects/pluginSwitch.json.php with a Referer header pointing to an external domain; requests originating from unusual IP addresses or user agents targeting this endpoint.
  • Logs: Web server access logs showing POST requests to objects/pluginSwitch.json.php with parameters uuid=<plugin-uuid>&status=inactive from unexpected referrers or at unusual times; absence of a valid CSRF token in the request body.
  • Application: Sudden disabling of security-critical plugins (LoginControl, access control, subscription enforcement) in the AVideo admin panel without a corresponding admin action; audit log entries (if enabled) showing plugin state changes not initiated by a known administrator session.
  • File System: No direct file system artifacts expected for this CSRF attack, but review AVideo database plugins table for unexpected status='inactive' entries on security-relevant plugins (GitHub Advisory).

Mitigation and workarounds

The recommended fix is to add CSRF token validation in objects/pluginSwitch.json.php immediately after the admin check, using AVideo's existing isGlobalTokenValid() function:

if (!isGlobalTokenValid()) { forbiddenPage('Invalid CSRF token'); }

Administrators should update to a version of AVideo that includes this fix (commits 7ddfe4e and da37510 are referenced in the advisory). As a workaround, restrict administrative access to trusted networks or VPN, and consider changing session cookie SameSite policy from None to Strict or Lax to reduce cross-origin cookie delivery. Regularly audit the plugin status in the admin panel to detect unauthorized changes (GitHub Advisory, Github Advisory DB).

Community reactions

The vulnerability was discovered and reported by aisafe.io and credited to researcher adrgs. The advisory was published by DanielnetoDotCom (the AVideo maintainer) on March 30, 2026. The CVE was noted on Bluesky via the CVE tracking account shortly after publication. No significant broader media coverage or notable researcher commentary beyond the advisory itself has been identified at this time (GitHub Advisory).

Additional resources


Source: This report was generated using AI

Related PHP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-55224HIGH8.7
  • PHP logoPHP
  • mineadmin/mineadmin
NoYesSep 30, 2026
CVE-2026-103111HIGH7.6
  • MariaDB Server logoMariaDB Server
  • mariadb11.8-server
NoYesSep 30, 2026
GHSA-3q6v-r5mr-hxv8HIGH7.5
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
GHSA-97jj-33gv-5xf9MEDIUM6.1
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
CVE-2026-104181MEDIUM5.4
  • PHP logoPHP
  • filament/filament
NoYesOct 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management