CVE-2026-92915: WWBN AVideo userVerifyEmail.php Unauthenticated Access Control
WWBN AVideo through commit e01e41ecc (no patched version available) contains a broken access control flaw in objects/userVerifyEmail.php. The script disables the login requirement ($global['ignoreUserMustBeLoggedIn'] = 1), takes usersid directly from the query string, and calls User::sendVerificationLink() with no session requirement, no CSRF/global token, no relationship check between caller and target, and no enforceRateLimit() call. The only intended throttle is keyed to the caller's own session, so cookie-less requests are never limited. An unauthenticated remote attacker can therefore cause an arbitrary number of verification emails to be sent to any account ID, and can enumerate accounts and their verification status from the three distinct JSON responses ("Verification Sent", "Already verified", "Unknown error"). In addition, createVerificationCode() invokes $user->setRecoverPass() and saves the user, so each anonymous request writes a live password-recovery token onto the targeted account; that token is embedded in base64 in the verification link emailed to the account owner and is accepted by objects/userRecoverPassSave.json.php as the credential for setting a new password.
Affected Software
Event History
Frequently Asked Questions
What does an attacker need to exploit this issue?
An attacker can exploit it remotely without authentication, a session, CSRF token, or cookies. They supply a target users_id in the query string to trigger the affected functionality.
Can this be used against accounts other than the attacker’s own account?
Yes. The endpoint does not check any relationship between the caller and the target users_id, so an unauthenticated requester can target arbitrary account IDs.
What are the security consequences beyond unwanted verification emails?
Each request creates and saves a live password-recovery token for the targeted account. That token is included in the verification link sent to the account owner and is accepted by the password-reset endpoint as a credential to set a new password.
Can an attacker determine whether account IDs exist or are already verified?
Yes. The endpoint returns distinct JSON responses for a sent verification message, an already verified account, and an unknown error, allowing account and verification-status enumeration.