Impact
AVideo releases up through version 29.0 allow unauthenticated users to send requests to the plugin/PlayLists/epg.json.php endpoint and retrieve sensitive data, including live‑stream keys, private Electronic Program Guide schedules, server identifiers, and user or playlist identifiers. The flaw is an authentication bypass that enables sequential probing of numeric identifiers to expose confidential streaming content and network topology. This vulnerability directly compromises content confidentiality and potentially reveals internal infrastructure details.
Affected Systems
All installations of the open‑source AVideo media platform from WWBN running versions 29.0 or earlier contain the vulnerable epg.json.php script. Any site that includes the PlayLists/epg.json.php component is at risk until a fix is issued.
Risk and Exploitability
The CVSS score of 8.7 classifies the vulnerability as high severity, and the lack of authentication requirements makes the exploit trivial over the network. Although an EPSS score is unavailable, the flaw’s simplicity and public disclosure suggest a realistic exploitation risk. Attackers can enumerate the endpoint with sequential numeric identifiers to extract private data, presenting a clear pathway for information theft. The vulnerability is not listed in CISA’s KEV catalog, but the impact remains significant for any deployed version.
OpenCVE Enrichment