Medium severity5.3NVD Advisory· Published Jan 10, 2024· Updated Jun 17, 2026
CVE-2023-50172
CVE-2023-50172
Description
A recovery notification bypass vulnerability exists in the userRecoverPass.php captcha validation functionality of WWBN AVideo dev master commit 15fed957fb. A specially crafted HTTP request can lead to the silent creation of a recovery pass code for any user.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
wwbn/avideoPackagist | <= 12.4 | — |
Affected products
3Patches
Vulnerability mechanics
References
5- talosintelligence.com/vulnerability_reports/TALOS-2023-1897nvdExploitThird Party AdvisoryWEB
- github.com/advisories/GHSA-8m5f-2xvp-2c8wghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2023-50172ghsaADVISORY
- github.com/WWBN/AVideo/commit/15fed957fb64b4055158acfc449bd7974346edb5ghsaWEB
- www.talosintelligence.com/vulnerability_reports/TALOS-2023-1897nvd
News mentions
0No linked articles in our index yet.