---
id: CVE-2020-37172
title: AVideo Platform 8.1 - Cross Site Request Forgery (Password Reset)
summary: >-
  AVideo Platform 8.1 contains a cross-site request forgery vulnerability that
  allows attackers to reset user passwords by exploiting the password recovery
  mechanism. Attackers can craft malicious requests to the recoverPass endpoint
  using…
severity: medium
cvss: 5.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'
cvssSource: cna
cwe:
  - CWE-640
vendor: AVideo
product: AVideo Platform
affected:
  - platform 8.1
ssvc:
  exploitation: poc
  automatable: 'yes'
  technicalImpact: partial
  timestamp: '2026-02-12T18:48:03.982687Z'
exploitAvailable: true
published: '2026-02-11'
updated: '2026-10-01'
sourceUpdated: '2026-10-01T15:19:37.612Z'
source: CVEORG
sourceUrl: 'https://www.cve.org/CVERecord?id=CVE-2020-37172'
references:
  - url: 'https://www.exploit-db.com/exploits/48003'
    label: ExploitDB-48003
  - url: 'https://avideo.com'
    label: Official AVideo Platform Homepage
  - url: 'https://github.com/WWBN/AVideo'
    label: AVideo GitHub Repository
  - url: >-
      https://www.vulncheck.com/advisories/avideo-platform-cross-site-request-forgery-password-reset
    label: >-
      VulnCheck Advisory: AVideo Platform 8.1 - Cross Site Request Forgery
      (Password Reset)
tags:
  - cve.org
  - exploit-available
epss: 0.00717
epssPercentile: 0.5211
ingestedAt: '2026-10-01T15:48:17.876Z'
---

## Overview

AVideo Platform 8.1 contains a cross-site request forgery vulnerability that allows attackers to reset user passwords by exploiting the password recovery mechanism. Attackers can craft malicious requests to the recoverPass endpoint using the user's recovery token to change account credentials without authentication.

## Affected

- `platform 8.1`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
