#VU125503 Cross-site request forgery in AVideo - CVE-2026-35180
Published: April 8, 2026
AVideo
World Wide Broadcast Network
Description
The vulnerability allows a remote attacker to overwrite the site logo.
The vulnerability exists due to cross-site request forgery in the site customization endpoint when handling crafted requests from a victim's browser. A remote attacker can trick a victim into submitting a specially crafted request to overwrite the site logo.
User interaction is required to trigger the crafted request.