Impact
MediaCMS 8.2.0 contains an information disclosure vulnerability that enables authenticated users, by adding arbitrary media tokens to their own playlist, to bypass access controls and view private metadata of other users. The flaw allows retrieval of sensitive fields such as title, description, view count, like count, file size, author username, and encoding status due to improper authorization handling (CWE‑863). This results in a significant confidentiality breach for affected users.
Affected Systems
MediaCMS, Version 8.2.0.
Risk and Exploitability
The CVSS score of 8.2 indicates a high impact. The EPSS score of less than 1% suggests low current exploitation likelihood, but the vulnerability is not yet listed in CISA KEV. Attackers must be authenticated to the system and can issue a PUT request to the playlist API endpoint with a known media token, thereby circumventing state and ownership validation. This path enables unauthorized read of private data without requiring elevated privileges or remote code execution.
OpenCVE Enrichment