CVE 8.7 HIGH

WWBN AVideo has a Path Traversal in Locale Save Endpoint that Enables Arbitrary PHP File Write to Any Web-Accessible Directory (RCE)_CVE-2026-40909

8.7 / 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N

Description

WWBN AVideo is an open source video platform. In versions 29.0 and prior, the locale save endpoint (`locale/save.php`) constructs a file path by directly concatenating `$_POST['flag']` into the path at line 30 without any sanitization. The `$_POST['code']` parameter is then written verbatim to that path via `fwrite()` at line 40. An admin attacker (or any user who can CSRF an admin, since no CSRF token is checked and cookies use `SameSite=None`) can traverse out of the `locale/` directory and write arbitrary `.php` files to any writable location on the filesystem, achieving Remote Code Execution. Commit 57f89ffbc27d37c9d9dd727212334846e78ac21a fixes the issue.

AI Analysis

Path Traversal vulnerability in WWBN AVideo locale save endpoint, allowing arbitrary PHP file write to any web-accessible directory, resulting in Remote Code Execution

Basic Information

ID CVE-2026-40909
Source GitHub_M
Published Apr 21, 2026 at 19:54
Modified Apr 21, 2026 at 20:36

Affected Product

Vendor WWBN
Product AVideo
Version <= 29.0
Affected Versions WWBN AVideo <= 29.0

CWE Classification

AI Assessment

AI Score 8.7 / 10
AI Severity High
Vendor WWBN
Product AVideo
Version <= 29.0

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.