CVE-2026-82647: WWBN AVideo Cross-Site Request Forgery via sendEmail.json.php
WWBN AVideo contains a cross-site request forgery vulnerability in sendEmail.json.php that allows authenticated administrators to send mail from the site's contact address by bypassing origin checks and captcha validation. Attackers can craft a malicious web page that, when visited by an authenticated admin, sends emails with attacker-controlled subject and body to arbitrary recipients, passing SPF/DKIM/DMARC validation for phishing and brand impersonation attacks.
Affected Software
Event History
Frequently Asked Questions
Who is exposed to exploitation?
Sites are exposed when an authenticated AVideo administrator visits an attacker-controlled malicious web page. The attacker does not need authentication, but successful exploitation requires the administrator to interact with the page while logged in.
What can an attacker do through this issue?
An attacker can cause the site to send emails from its contact address to arbitrary recipients with attacker-controlled subjects and bodies. The resulting messages can pass SPF, DKIM, and DMARC validation, enabling phishing or brand impersonation using the site's mail identity.
How can I tell whether exploitation may have occurred?
Review outbound email records for messages sent from the site's contact address with unexpected recipients, subjects, or content. Pay particular attention to messages that administrators did not intentionally send.