Impact
A cross‑site request forgery flaw resides in the logArchive.json.php endpoint of WWBN AVideo. The endpoint accepts a GET request without requiring a CSRF token, allowing an unauthenticated attacker to cause an administrator’s browser to archive application logs. The logs are then stored in a publicly accessible ZIP file, and the live log file is truncated, removing forensic evidence. This results in a confidentiality breach, impact on log gathering.
Affected Systems
The vulnerability affects installations of WWBN AVideo that include or precede the commit c3edcc274c389816d434acadac07ee78eaf330c1. All versions lacking the recent patch are susceptible. No specific product version ranges are provided beyond the commit hash.
Risk and Exploitability
The CVSS score of 7.1 indicates moderate severity. The EPSS score is not available and the vulnerability is not listed in CISA KEV. The likely attack path involves an attacker hosting a malicious web page that an administrator unknowingly visits, thereby sending a GET request to the vulnerable endpoint. Successful exploitation delivers sensitive logs to the attacker and deletes the original log contents, creating a high impact on confidentiality and evidence retention.
OpenCVE Enrichment