#VU125502 Cross-site request forgery in AVideo - CVE-2026-35181
Published: April 8, 2026
AVideo
World Wide Broadcast Network
Description
The vulnerability allows a remote attacker to modify player skin configuration.
The vulnerability exists due to improper request validation in admin/playerUpdate.json.php when handling crafted cross-site requests. A remote attacker can trick a victim into submitting a crafted request to modify player skin configuration.
User interaction is required to trigger the request.