CVE-2020-37158
MEDIUMAVideo Platform 8.1 - CSRF
Title source: llmDescription
AVideo Platform 8.1 contains a cross-site request forgery vulnerability that allows attackers to reset user passwords by exploiting the password recovery mechanism. Attackers can craft malicious requests to the recoverPass endpoint using the user's recovery token to change account credentials without authentication.
Exploits (1)
Scores
CVSS v3
5.3
EPSS
0.0002
EPSS Percentile
4.1%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Classification
CWE
CWE-352
CWE-640
Status
published
Affected Products (1)
wwbn/avideo
Timeline
Published
Feb 11, 2026
Tracked Since
Feb 18, 2026