CVE-2026-90537 | WWBN AVideo Scheduler Email sendEmail.json.php sendEmail daily token improper authorization
A vulnerability, which was classified as critical, was found in WWBN AVideo. This issue affects the function sendEmail of the file plugin/Scheduler/sendEmail.json.php of the component Scheduler Email. Executing a manipulation of the argument daily token can lead to improper authorization.
This vulnerability is tracked as CVE-2026-90537. The attack can be launched remotely. No exploit exists.
It is advisable to implement a patch to correct this issue.VulDB Recent EntriesRead More