CVE-2026-40925 | WWBN AVideo up to 29.0 configurationUpdate.json.php User::isAdmin cross-site request forgery (EUVD-2026-24485)
A vulnerability was found in WWBN AVideo up to 29.0. It has been declared as problematic. The impacted element is the function User::isAdmin of the file objects/configurationUpdate.json.php. Such manipulation leads to cross-site request forgery.
This vulnerability is traded as CVE-2026-40925. The attack may be launched remotely. There is no exploit available.
It is best practice to apply a patch to resolve this issue.