Impact
WWBN AVideo contains an SSRF vulnerability in the _json_decode function used by login.json.php. The function accepts arbitrary file paths or HTTP URLs without performing SSRF validation and returns the retrieved content parsed as login credentials. An attacker can exploit this by sending, causing the server to read local files or reach internal services and disclose the data in the response. This exposes sensitive configuration or credential information and can serve as a foothold for further compromise.
Affected Systems
The vulnerability affects the WWBN AVideo application. No specific affected versions are listed in the vulnerable until a fix is applied.
Risk and Exploitability
The CVSS score of 6.9 indicates a medium severity vulnerability. The exploitation can be performed without authentication by sending a carefully crafted POST request to login.json.php, making the threat vector broadly reachable. Although the EPSS score is not available and the vulnerability is not listed in KEV, the lack of input validation means an unauthenticated attacker can read local files or internal service responses, potentially exposing critical data. The risk is moderate, with a realistic chance of exploitation in environments where the application server can reach internal networks.
OpenCVE Enrichment