A recovery notification bypass vulnerability exists in the userRecoverPass.php captcha validation functionality of WWBN AVideo dev master commit 15fed957fb. A specially crafted HTTP request can lead to the silent creation of a recovery pass code for any user.
| Software | From | Fixed in |
|---|---|---|
wwbn / avideo
|
- | 12.4.x |
wwbn / avideo
|
15fed957fb | 15fed957fb.x |