Impact
WWBN AVideo fails to verify that the live_restreams_id supplied to resendRestreamer.json.php belongs to the requesting user, allowing an authenticated user with the canStream permission to access and hijack other users' restream destinations. This flaw exposes the victim’s stream keys, enabling attackers to broadcast their own content to the victim’s YouTube, Facebook, or Twitch channels. The vulnerability is an instance of Missing Authorization (CWE-639) that compromises confidentiality and the integrity of user streams, and can disrupt the victim’s broadcast schedule.
Affected Systems
The issue appears in the WWBN AVideo repository under commit c3edcc274c389816d434acadac07ee78eaf330c1. No specific product version range is listed, but any installations using this commit or later without the fix are vulnerable.
Risk and Exploitability
With a CVSS score of 8.6 the flaw is considered high severity. Exploitation requires an authenticated account with canStream rights; the attacker submits arbitrary live_restreams_id values to resendRestreamer.json.php. The vulnerability is internal to the web application, so attack is limited to users who can log in, but once compromised, the attacker can hijack external streaming services using the victim’s credentials. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting that public exploitation is not currently widespread but could be possible should attackers gain legitimate credentials.
OpenCVE Enrichment