Impact
WWBN AVideo exposes a server‑side request forgery flaw in the set_api_userImages endpoint that accepts profileImg and backgroundImg URLs without proper validation. Authenticated API clients can supply internal or cloud‑metadata URLs; the server retrieves the content and stores it in publicly accessible web paths. This flaw can be used to read internal resources or leak sensitive information such as cloud instance metadata, internal service responses, or other protected data. The vulnerability is classified as CWE‑918, indicating an authentication‑bound SSRF that can lead to information disclosure.
Affected Systems
The affected system is the WWBN AVideo application. Specific version details are not provided in the public advisory; users of any unpatched AVideo environment should verify whether the commit c91b5975d or earlier releases are in use.
Risk and Exploitability
With a CVSS score of 7.1 the vulnerability is considered high severity. Exploitation requires only a legitimate API authentication token, which may be available to legitimate users or compromised credentials. The EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog, suggesting the risk of exploitation in the wild is uncertain but potential exposure of internal data remains significant.
OpenCVE Enrichment