THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-58003 (HIGH 7.1) — WWBN AVideo through commit 9c39d8c8 contains a cross-site request forgery vulnerability in the releaseVideoNow.json.php endpoint that lacks authenticity checks and accepts GET requests. Attackers can craft a malicious cross-site GET request carrying an administrator's session coo

[NVD] CVE-2026-58003 (HIGH 7.1) — WWBN AVideo through commit 9c39d8c8 contains a cross-site request forgery vulnerability in the releaseVideoNow.json.php endpoint that lacks authenticity checks and accepts GET requests. Attackers can craft a malicious cross-site GET request carrying an administrator's session coo

mednvdPublished 2026-08-22

CVE-2026-58003 CVSS: 7.1 HIGH Published: 2026-08-22T13:16:38.673

WWBN AVideo through commit 9c39d8c8 contains a cross-site request forgery vulnerability in the releaseVideoNow.json.php endpoint that lacks authenticity checks and accepts GET requests. Attackers can craft a malicious cross-site GET request carrying an administrator's session cookie to permanently publish any embargoed video by mani

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-58003