Apr 2, 2026
Broken Cloud Update - 2026-04-01 16:13 UTC
Another day, another dependency betrayal. 🔐 AVideo CSRF Blob admin/save.json.php lacks CSRF. Logged‑in admin visits evil site → S3 keys, PayPal mail, plugin config overwritten. SameSite=None cookie makes it trivial. GHSA-4wwr-7h7c-chqr.