AVideo Platform 8.1 contains a cross-site request forgery vulnerability that allows attackers to reset user passwords by exploiting the password recovery mechanism. Attackers can craft malicious requests to the recoverPass endpoint using the user's recovery token to change account credentials without authentication.
History

Thu, 12 Feb 2026 09:45:00 +0000

Type Values Removed Values Added
First Time appeared Avideo
Avideo avideo Platform
Vendors & Products Avideo
Avideo avideo Platform

Wed, 11 Feb 2026 22:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 11 Feb 2026 21:00:00 +0000

Type Values Removed Values Added
Description AVideo Platform 8.1 contains a cross-site request forgery vulnerability that allows attackers to reset user passwords by exploiting the password recovery mechanism. Attackers can craft malicious requests to the recoverPass endpoint using the user's recovery token to change account credentials without authentication.
Title AVideo Platform 8.1 - Cross Site Request Forgery (Password Reset)
Weaknesses CWE-640
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}

cvssV4_0

{'score': 8.5, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published: 2026-02-11T20:49:49.113Z

Updated: 2026-02-11T21:44:10.637Z

Reserved: 2026-02-03T16:27:45.310Z

Link: CVE-2020-37158

cve-icon Vulnrichment

Updated: 2026-02-11T21:43:06.492Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-02-11T21:16:08.617

Modified: 2026-02-12T15:10:37.307

Link: CVE-2020-37158

cve-icon Redhat

No data.