Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-34362

Опубликовано: 27 мар. 2026
Источник: nvd
CVSS3: 5.4
EPSS Низкий

Описание

WWBN AVideo is an open source video platform. In versions up to and including 26.0, the verifyTokenSocket() function in plugin/YPTSocket/functions.php has its token timeout validation commented out, causing WebSocket tokens to never expire despite being generated with a 12-hour timeout. This allows captured or legitimately obtained tokens to provide permanent WebSocket access, even after user accounts are deleted, banned, or demoted from admin. Admin tokens grant access to real-time connection data for all online users including IP addresses, browser info, and page locations. Commit 5d5237121bf82c24e9e0fdd5bc1699f1157783c5 fixes the issue.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:wwbn:avideo:*:*:*:*:*:*:*:*
Версия до 26.0 (включая)

EPSS

Процентиль: 16%
0.00247
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-613

Связанные уязвимости

CVSS3: 5.4
github
4 месяца назад

AVideo's WebSocket Token Never Expires Due to Commented-Out Timeout Validation in verifyTokenSocket()

EPSS

Процентиль: 16%
0.00247
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-613