Impact
AVideo versions through 29.0 contain an IDOR flaw in the objects/categoryDeleteAssets.json.php endpoint, where only a canCreateCategory capability and a CSRF nonce are verified. The endpoint then passes recursively removing the on‑disk asset directory of that category. The ownership check enforced by delete() is omitted, so a non‑admin user who has the canUpload and category‑create permissions, though the database records and video files remain intact.
Affected Systems
Any WWBN AVideo installation up to and including version 29.0 where the non‑default usersCanCreateNewCategories setting is enabled. The flaw affects installations that expose the endpoint to authenticated users possessing the canUpload capability.
Risk and Exploitability
The CVSS score is 5.3, indicating moderate severity. EPSS is not provided and the vulnerability is not listed in KEV. Exploitation requires a legitimate user account with the canUpload and category‑create permissions; an attacker must send a crafted POST request to the vulnerable endpoint. Due to the need for authenticated access, the attack vector is limited to users who have legitimate access but potentially misconfigured permissions.
OpenCVE Enrichment