Cross-site request forgery in AVideo - CVE-2026-33649
Published: May 4, 2026
AVideo
Detailed vulnerability description
The vulnerability allows a remote attacker to escalate privileges.
The vulnerability exists due to improper access control in setPermission.json.php when handling GET requests that modify permissions. A remote attacker can trick a victim into following a crafted link to escalate privileges.
User interaction is required to follow the crafted link.