#VU125485 Insufficient Session Expiration in AVideo - CVE-2026-34362
Published: April 8, 2026
AVideo
World Wide Broadcast Network
Description
The vulnerability allows a remote user to disclose sensitive information and impersonate users over WebSocket connections.
The vulnerability exists due to insufficient session expiration in verifyTokenSocket() in plugin/YPTSocket/functions.php when validating WebSocket tokens. A remote user can reuse a captured or previously obtained WebSocket token to disclose sensitive information and impersonate users over WebSocket connections.
Admin tokens can expose real-time connection data for online users, including IP addresses, browser information, and page locations, and tokens remain usable even after account deletion, banning, or privilege demotion.