CVE-2020-37172

AVideo Platform 8.1 contains a cross-site request forgery vulnerability that allows attackers to reset user passwords by exploiting the password recovery mechanism. Attackers can craft malicious requests to the recoverPass endpoint using the user's recovery token to change account credentials without authentication.
Configurations

Configuration 1 (hide)

cpe:2.3:a:wwbn:avideo:8.1:*:*:*:*:*:*:*

History

18 Feb 2026, 19:37

Type Values Removed Values Added
References () https://avideo.com - () https://avideo.com - Product
References () https://github.com/WWBN/AVideo - () https://github.com/WWBN/AVideo - Product
References () https://www.exploit-db.com/exploits/48003 - () https://www.exploit-db.com/exploits/48003 - Exploit, Third Party Advisory, VDB Entry
References () https://www.vulncheck.com/advisories/avideo-platform-cross-site-request-forgery-password-reset - () https://www.vulncheck.com/advisories/avideo-platform-cross-site-request-forgery-password-reset - Third Party Advisory
First Time Wwbn
Wwbn avideo
CPE cpe:2.3:a:wwbn:avideo:8.1:*:*:*:*:*:*:*

11 Feb 2026, 21:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-11 21:16

Updated : 2026-02-18 19:37


NVD link : CVE-2020-37172

Mitre link : CVE-2020-37172

CVE.ORG link : CVE-2020-37172


JSON object : View

Products Affected

wwbn

  • avideo
CWE
CWE-640

Weak Password Recovery Mechanism for Forgotten Password