Daniel Neto
118 exploits
Active since May 2023
WWBN AVideo Vulnerable to CSRF in Admin JSON Endpoints (Category CRUD, Plugin Update Script)
CVSS 7.1
AVideo: Missing CSRF Protection on State-Changing JSON Endpoints Enables Forced Comment Creation, Vote Manipulation, and Category Asset Deletion
CVSS 5.4
WWBN AVideo's missing CSRF protection in objects/commentDelete.json.php enables mass comment deletion against moderators and content creators
CVSS 5.4
WWBN/AVideo has CAPTCHA Bypass via Attacker-Controlled Length Parameter and Missing Token Invalidation on Failure
CVSS 5.3
WWBN AVideo LiveLinks Proxy - Server-Side Request Forgery
CVSS 8.6
AVideos has CORS Origin Reflection with Credentials on Sensitive API Endpoints that Enables Cross-Origin Account Takeover
CVSS 8.1
AVideo has CORS Origin Reflection Bypass via plugin/API/router.php and allowOrigin(true) that Exposes Authenticated API Responses
CVSS 7.1
AVideo <=29.0 CloneSite deleteDump - Path Traversal
CVSS 8.1
AVideo's SSRF via same-domain hostname with alternate port bypasses isSSRFSafeURL
CVSS 7.7
WWBN AVideo Vulnerable to stored XSS via Unanchored Duration Regex in Video Encoder Receiver
CVSS 5.4
AVideo <=29.0 ReceiveImage downloadURL - Path Traversal
CVSS 6.5
WWBN AVideo ParsedownSafeWithLinks - Cross-Site Scripting
CVSS 5.4
AVideo <=29.0 test.php URL Handling - Command Injection
CVSS 9.3
WWBN AVideo vulnerable to RCE caused by clonesite plugin
WWBN AVideo Affected by a PayPal IPN Replay Attack Enabling Wallet Balance Inflation via Missing Transaction Deduplication in ipn.php
CVSS 6.5
WWBN AVideo has Stored XSS via Malicious EPG XML Program Titles in AVideo EPG Page
CVSS 5.4
AVideo: Unauthenticated IDOR in playlistsVideos.json.php Exposes Private Playlist Contents
CVSS 5.3
AVideo: Unauthenticated Access to Scheduler Plugin Endpoints Leaks Scheduled Tasks, Email Content, and User Mappings
CVSS 5.3
AVideo <=26.0 Video Password Oracle - Brute Force
CVSS 5.3
AVideo: IDOR in AI Plugin Allows Stealing Other Users' AI-Generated Metadata and Transcriptions
CVSS 4.3
AVideo has SSRF Protection Bypass via HTTP Redirect in Image Download Endpoints
CVSS 6.5
AVideo has SQL Injection via Partial Prepared Statement — videos_id Concatenated Directly into Query
CVSS 8.8
AVideo has SQL Injection in category.php fixCleanTitle() via Unparameterized clean_title and id Variables
CVSS 9.8
AVideo has Plaintext Video Password Storage
CVSS 7.5
AVideo's Missing Authorization in Playlist Schedule Creation Allows Cross-User Broadcast Hijacking
CVSS 6.3