Impact
WWBN AVideo fails to enforce authorization on its adsInfo API endpoint, allowing unauthenticated callers to supply a videos_id parameter and receive the video owner’s user ID along with personalized advertisement URLs. This vulnerability is a classic example of information exposure (CWE‑200), enabling disclosure of otherwise protected identifiers that could.
Affected Systems
The flaw exists in the WWBN AVideo platform and is present in any installation prior to the fix committed as c3edcc274c389816d434acadac07ee78eaf330c1. Affected versions are all releases of WWBN AVideo that have not yet applied this commit or later interim patches. The product is available under the vendor name WWBN, product AVideo.
Risk and Exploitability
The CVSS base score of 6.9 signals a moderate risk of impact, and no EPSS value is currently available, so exploitation likelihood cannot be quantified precisely. The vulnerability is not listed in the CISA KEV catalog. Attackers can reach the adsInfo endpoint over the network; the likely attack to the service. Once the endpoint is accessed, the attacker immediately obtains the identifiers and ad URLs, bypassing any authentication or permission checks. The impact is primarily loss of confidentiality of user identifiers and potential exposure of advertising content.
OpenCVE Enrichment