THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-81733 — WWBN AVideo through 30.0 (and master up to commit 4cb576e) contains a cross-site request forgery vulnerability in plugin/Live/myLiveControls.save.json.php. The endpoint only checks that a user is logged in and processes customUrl, customMessage, and autoRedirect parameters from $

[NVD] CVE-2026-81733 — WWBN AVideo through 30.0 (and master up to commit 4cb576e) contains a cross-site request forgery vulnerability in plugin/Live/myLiveControls.save.json.php. The endpoint only checks that a user is logged in and processes customUrl, customMessage, and autoRedirect parameters from $

mednvdPublished 2026-08-28

CVE-2026-81733 CVSS: None Published: 2026-08-28T12:16:32.350

WWBN AVideo through 30.0 (and master up to commit 4cb576e) contains a cross-site request forgery vulnerability in plugin/Live/myLiveControls.save.json.php. The endpoint only checks that a user is logged in and processes customUrl, customMessage, and autoRedirect parameters from $_REQUEST via a GET request without enforcing a CSRF token

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-81733