CyberRota Analysis
AI-GeneratedThe vulnerability exists in the sendEmail.json.php file of WWBN AVideo, allowing authenticated administrators to be exploited via cross-site request forgery. Attackers can leverage this flaw to send emails from the site's contact address, bypassing origin checks and captcha validation, which can facilitate phishing and brand impersonation attacks. Organizations using AVideo should prioritize addressing this vulnerability to protect against potential misuse by malicious actors.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
WWBN AVideo contains a cross-site request forgery vulnerability in sendEmail.json.php that allows authenticated administrators to send mail from the site's contact address by bypassing origin checks and captcha validation. Attackers can craft a malicious web page that, when visited by an authenticated admin, sends emails with attacker-controlled subject and body to arbitrary recipients, passing SPF/DKIM/DMARC validation for phishing and brand impersonation attacks.