WWBN AVideo fails to validate password recovery token expiration in userRecoverPassSave.json.php, allowing attackers to use expired tokens to reset account passwords indefinitely. Attackers who obtain a recovery token can use it at any time to change the target account's password and gain full account access.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-09-01 23:17
Updated : 2026-09-08 20:18
NVD link : CVE-2026-84480
Mitre link : CVE-2026-84480
CVE.ORG link : CVE-2026-84480
JSON object : View
Products Affected
No product.
CWE
CWE-613
Insufficient Session Expiration
