Impact
WWBN AVideo has a broken access control flaw in the public feed/index.php endpoint. When a program_id parameter is supplied, the per‑video visibility checks are bypassed, allowing an attacker to collect the RSS feed for any playlist ID. This enables enumeration of playlist identifiers and retrieval of unlisted and group‑restricted videos, exposing the entire hidden video catalogue without authentication. The vulnerability is classified as CWE‑200.
Affected Systems
The affected product is WWBN AVideo. No specific version numbers are provided in the advisory, implying that all releases of the application may be vulnerable until a fix is deployed. The endpoint is reachable over the public web, so every instance exposed to the internet is a potential target.
Risk and Exploitability
The CVSS score of 6.9 indicates moderate severity. No EPSS score is available, and the vulnerability is not listed in CISA KEV. Attackers only need to send HTTP requests to the RSS feed with different program_id values; no special privileges are required. The simplicity of the exploit and the possibility of full catalogue disclosure make the risk of confidentiality compromise considerable. The likely attack vector is network‑based, with attackers leveraging public HTTP access to enumerate and extract hidden media resources.
OpenCVE Enrichment