Impact
The vulnerability is an unauthenticated information disclosure flaw, identified as CWE-306, located in the plugin/Live/stats.json.php file of AVideo versions through 29.0. It enables attackers to retrieve stream keys and m3u8 URLs by accessing the exposed endpoint without authentication. By parsing the hidden_applications array in the JSON response, an attacker can enumerate private, unlisted, and group-restricted live streams, thereby accessing sensitive streaming credentials and potentially violating confidentiality and availability of the content.
Affected Systems
The vulnerability affects the WWBN AVideo platform, specifically all releases up to and including version 29.0. Users running these or older versions are susceptible to the data leak.
Risk and Exploitability
The flaw carries a CVSS score of 8.7, indicating a high severity. The EPSS score is not available, and the vulnerability has not been listed in the CISA KEV catalog. Attackers need only send an HTTP request to the publicly exposed stats.json.php endpoint; no prior authentication or privileged access is required. The risk is therefore direct and immediate for any unpatched installation.
OpenCVE Enrichment