Impact
A missing authentication and authorization check in the WebRTC plugin’s status.json.php endpoint lets any remote, unauthenticated user obtain a JSON payload that reveals the absolute filesystem path to the WebRTC2RTMP helper binary, the configured WebRTC port, the binary’s exist‑and‑executable status, the contents of log files when present, and the reachability of the configured port on loopback and on the public interface. The exposed data reveals internal directory structure and runtime configuration, potentially aiding further attacks. This weakness is a classic CWE‑200 Information Exposure flaw.
Affected Systems
The vulnerability affects WWBN AVideo with the WebRTC plugin in all releases that include the code at commit c3edcc274c389816d434acadac07ee78eaf330c1 as of the reporting date. All current releases contain the vulnerability; a patch has not yet been released.
Risk and Exploitability
The CVSS score of 6.9 indicates a medium severity risk. No EPSS score is available, and the vulnerability is not currently listed in CISA’s KEV catalog, so the quantified likelihood of exploitation is unknown. The attack can be carried out with no authentication by simply sending an HTTP GET request to /plugin/WebRTC/status.json.php on the target where the WebRTC plugin is installed. Because the endpoint performs no User::isLogged(), User::isAdmin(), or forbiddenPage() checks, any unauthenticated actor can gain the described information, which could facilitate further reconnaissance or exploitation steps.
OpenCVE Enrichment