Impact
WWBN AVideo contains a broken access control flaw that allows any visitor to the public channel page to view private, unlisted, and group‑restricted video content. The flaw arises from a hardcoded visibility flag and an undefined property that bypasses the operator’s hidePrivateVideos setting. The consequence is the accidental exposure of full video URLs and thumbnails, leading to confidentiality compromise of content that should otherwise remain hidden.
Affected Systems
The vulnerability affects the WWBN:AVideo product. No specific patch version or affected release is listed in the CVE data, so all deployments of this software are potentially impacted until a fix is applied.
Risk and Exploitability
The CVSS score is 6.9, indicating a moderate severity. The EPSS score is not available and the vulnerability is not listed in CISA KEV, suggesting no known active exploitation campaigns. Attackers can exploit the flaw by simply navigating to the affected channel endpoint—no authentication is required. Once reached, they can retrieve sensitive video URLs and thumbnails that are intended to be private.
OpenCVE Enrichment