Impact
The vulnerability in the restreamsActive.json.php endpoint allows an authenticated streamer to retrieve the source stream keys and identities of all active restreams owned by other users. This results in an unintended disclosure of transmission credentials and the identities of streamers across accounts, exposing sensitive data that should be protected by the application.
Affected Systems
AVideo software produced by WWBN versions 29.0 and earlier are affected. No specific patch level is indicated in the advisory, so any deployment using AVideo 29.0 or an older release will contain the flaw.
Risk and Exploitability
The CVSS score of 7.1 indicates a moderate to high severity risk. The EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog. The attack vector requires an attacker to be logged in with streamer privileges; once authenticated, the attacker can enumerate all active streams of other streamers. Because the source stream keys are disclosed, an adversary could tap into or hijack other users’ live streams, representing a significant confidentiality breach.
OpenCVE Enrichment