AVideo through commit 9c39d8c8 contains a cross-site request forgery vulnerability in channelToGallery.json.php that allows attackers to modify site-wide Gallery configuration by performing unauthorized writes to plugin data. Attackers can craft a cross-site GET request carrying an administrator's session cookie to promote arbitrary channels to the front page or delete curated sections without token validation.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-08-22 13:16
Updated : 2026-08-26 18:16
NVD link : CVE-2026-57944
Mitre link : CVE-2026-57944
CVE.ORG link : CVE-2026-57944
JSON object : View
Products Affected
No product.
CWE
CWE-352
Cross-Site Request Forgery (CSRF)
