AVideo Platform 8.1 contains a cross-site request forgery vulnerability that allows attackers to reset user passwords by exploiting the password recovery mechanism. Attackers can craft malicious requests to the recoverPass endpoint using the user's recovery token to change account credentials without authentication.
History

Wed, 11 Feb 2026 22:15:00 +0000

Type Values Removed Values Added
First Time appeared Avideo
Avideo avideo Platform
Vendors & Products Avideo
Avideo avideo Platform

Wed, 11 Feb 2026 20:45:00 +0000

Type Values Removed Values Added
Description AVideo Platform 8.1 contains a cross-site request forgery vulnerability that allows attackers to reset user passwords by exploiting the password recovery mechanism. Attackers can craft malicious requests to the recoverPass endpoint using the user's recovery token to change account credentials without authentication.
Title AVideo Platform 8.1 - Cross Site Request Forgery (Password Reset)
Weaknesses CWE-640
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}

cvssV4_0

{'score': 8.5, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published: 2026-02-11T20:33:33.722Z

Updated: 2026-02-11T20:36:57.220Z

Reserved: 2026-02-10T17:46:27.015Z

Link: CVE-2020-37172

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-02-11T21:16:09.470

Modified: 2026-02-11T21:16:09.470

Link: CVE-2020-37172

cve-icon Redhat

No data.