Impact
A vulnerability exists in the PlayerSkins plugin of AVideo where the seo.php endpoint does not enforce password validation when retrieving video sources. Unauthenticated users can request this endpoint with a video identifier and obtain the direct MP4 URL, allowing them to read protected media bytes without supplying the configured password. The flaw results in confidential video content being disclosed to anyone who can construct the request.
Affected Systems
The issue affects installations of AVideo that include the PlayerSkins plugin and are running any revision prior to the fix identified by commit c3edcc274c389816d434acadac07ee78eaf330c1. All instances of the seo.php endpoint under the plugin are vulnerable.
Risk and Exploitability
The CVSS score of 8.7 indicates a high severity that can be exploited remotely by sending a crafted HTTP request to seo.php. EPSS data is not available, but the lack of authentication requirements means any web‑connected host can be targeted. The vulnerability is not listed in CISA KEV, yet the potential for mass media distribution makes it a high‑risk exposure. Attackers can directly request the endpoint with a video ID, bypassing any password security, and receive the media URL for download or manipulation.
OpenCVE Enrichment