โ† Back to all CVEs

CVE-2026-33649

HIGH NVD
CVSS Score 8.1
Severity HIGH
Published Mar 23, 2026
Vendor unknown

Description

WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `plugin/Permissions/setPermission.json.php` endpoint accepts GET parameters for a state-changing operation that modifies user group permissions. The endpoint has no CSRF token validation, and the application explicitly sets `session.cookie_samesite=None` on session cookies. This allows an unauthenticated attacker to craft a page with `<img>` tags that, when visited by an admin, silently grant arbitrary permissions to the attacker's user group โ€” escalating the attacker to near-admin access. As of time of publication, no known patched versions are available.

References