Skip to content

Menu
  • Home
Menu

CVE-2026-84480 – WWBN AVideo Password Recovery Token Expiration Bypass

Posted on September 2, 2026
CVE ID :CVE-2026-84480

Published : Sept. 1, 2026, 11:17 p.m. | 1 hour, 19 minutes ago

Description :WWBN AVideo fails to validate password recovery token expiration in userRecoverPassSave.json.php, allowing attackers to use expired tokens to reset account passwords indefinitely. Attackers who obtain a recovery token can use it at any time to change the target account’s password and gain full account access.

Severity: 9.8 | CRITICAL

Visit the link for more details, such as CVSS details, affected products, timeline, and more…

Post Views: 1

Site map

  • About Us
  • Privacy Policy
  • Terms & Conditions of Use
©2026 | Design: Newspaperly WordPress Theme