Impact
The vulnerability in WWBN AVideo surfaces when an attacker accesses the getRecordedFile.php endpoint without any authentication. The script expects a stream key and streams the requested FLV file from a temporary directory. Because the code lacks authentication checks, an attacker can supply a known or guessed stream key, causing the server to transmit the corresponding recorded live video to the requester. The result is a full disclosure of sensitive video content, with confidentiality entirely compromised. This flaw is classified as an unauthenticated read, aligning with CWE-306.
Affected Systems
The bug exists in the AVideo code base at commit c3edcc274c389816d434acadac07 deployment of WWBN AVideo that has not applied a subsequent patch or update is vulnerable. The affected component is the getRecordedFile.php file, which is part of the core AVideo distribution. No specific product version numbers are cited, but the vulnerability applies to the released code before the identified commit.
Risk and Exploitability
The CVSS score of 8.7 indicates a high severity vulnerability. Because the entry is publicly known but EPSS is not available, the current exploitation probability cannot be quantified, and the issue is not listed in CISA’s KEV catalog. Attackers could exploit the flaw over the network by issuing an unauthenticated HTTP GET request to the aforementioned endpoint with a valid stream key. Since no authentication or authorization gates exist, the risk to all users of the affected by anyone.
OpenCVE Enrichment