VYPR
High severity7.1NVD Advisory· Published Sep 10, 2026· Updated Sep 10, 2026

CVE-2026-88872

CVE-2026-88872

Description

AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a cross-site request forgery vulnerability in the setPassword.json.php endpoint that allows unauthenticated attackers to modify any user's channel password by sending a GET request. Attackers can craft a malicious webpage that, when visited by an authenticated administrator, sets or clears any user's channel password without CSRF token validation.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • AVideo/AVideollm-fuzzy
  • WWBN/Avideollm-fuzzy2 versions
    (expand)+ 1 more
    • (no CPE)
    • (no CPE)range: <c3edcc274c389816d434acadac07ee78eaf330c1

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.