#VU125492 Cross-site request forgery in AVideo - CVE-2026-34613
Published: April 8, 2026
AVideo
World Wide Broadcast Network
Description
The vulnerability allows a remote attacker to disable security plugins.
The vulnerability exists due to improper access control in the plugin enable/disable endpoint when handling cross-site requests. A remote attacker can trick the victim into sending a crafted request to disable security plugins.
User interaction is required for exploitation.