PT-2026-34200 · Avideo · Avideo

Published

2026-04-14

·

Updated

2026-04-26

·

CVE-2026-40935

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions AVideo versions prior to 29.1
Description In the open source video platform AVideo, the endpoint "objects/getCaptcha.php" accepts the CAPTCHA length via the ql query string parameter without clamping or sanitization. This allows unauthenticated clients to force the server to generate a 1-character CAPTCHA word. Because the system uses a case-insensitive strcasecmp comparison over a 33-character alphabet and failed validations do not consume the stored session token, an attacker can brute-force the CAPTCHA on any endpoint utilizing the Captcha::validation() function, such as user registration, password recovery, and contact forms, in approximately 33 requests per session.
Recommendations Update to a version later than 29.0 that includes commit bf1c76989e6a9054be4f0eb009d68f0f2464b453.

Exploit

Fix

Weakness Enumeration

Related Identifiers

CVE-2026-40935
GHSA-HG7G-56H5-5PQR

Affected Products

Avideo