Impact
The vulnerability exists in AVideo’s addLiveLink.php endpoint. During LiveLink updates the code fails to verify that the requestor owns the link being modified, representing an authorization bypass (CWE‑639). An authenticated user with the canStream role can therefore supply an existing linkId pointing to another user’s LiveLink and change its HLS source and metadata, effectively hijacking the link. The attacker’s control over the media source enables redirection of legitimate viewers to attacker‑controlled streams, compromising the integrity of the content.
Affected Systems
The issue affects the AVideo repository from WWBN, specifically the state of the code containing commit c3edcc274c389816d434acadac07ee78eaf330c1. No specific product versions are listed, so any deployed instance running the vulnerable code is potentially affected.
Risk and Exploitability
The CVSS score of 7.1 to authenticated users, the exploitation path requires the attacker to be logged in as a canStream user, which is a common privilege. The EPSS score is not available and the vulnerability is not yet listed in the CISA KEV catalog, which suggests limited public exploitation but still poses a significant risk for organizations that allow many users the canStream role. The attacker can redirect viewers to malicious content by updating the HLS source field of an existing LiveLink.
OpenCVE Enrichment