#VU125493 Cross-site request forgery in AVideo - CVE-2026-34611
Published: April 8, 2026
AVideo
World Wide Broadcast Network
Description
The vulnerability allows a remote attacker to send phishing email to all users.
The vulnerability exists due to missing cross-site request forgery protection in emailAllUsers.json.php when handling requests to send email to all users. A remote attacker can trick a victim into submitting a crafted request to send phishing email to all users.
User interaction is required.