Vulnerability Description
WWBN AVideo contains a cross-site request forgery vulnerability in sendEmail.json.php that allows authenticated administrators to send mail from the site's contact address by bypassing origin checks and captcha validation. Attackers can craft a malicious web page that, when visited by an authenticated admin, sends emails with attacker-controlled subject and body to arbitrary recipients, passing SPF/DKIM/DMARC validation for phishing and brand impersonation attacks.
CVSS Score
MEDIUM
Related Weaknesses (CWE)
References
- https://github.com/WWBN/AVideo/security/advisories/GHSA-7h9v-f3gg-r3mq
- https://www.vulncheck.com/advisories/wwbn-avideo-cross-site-request-forgery-via-
- https://github.com/WWBN/AVideo/security/advisories/GHSA-7h9v-f3gg-r3mq
FAQ
What is CVE-2026-82647?
CVE-2026-82647 is a vulnerability with a CVSS score of 6.1 (MEDIUM). WWBN AVideo contains a cross-site request forgery vulnerability in sendEmail.json.php that allows authenticated administrators to send mail from the site's contact address by bypassing origin checks a...
How severe is CVE-2026-82647?
CVE-2026-82647 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-82647?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.