Impact
WWBN AVideo fails to enforce authorization on its adsInfo API endpoint, allowing anyone with network access to query the endpoint with a videos_id parameter and obtain the video owner's user ID and associated advertisement URLs. This missing authorization results in the disclosure of otherwise protected identifiers and privacy‑related data, which the identified weakness (CWE-200) demonstrates is an information exposure vulnerability.
Affected Systems
The flaw exists in the WWBN AVideo platform. All releases prior to the commit c3edcc274c389816d434acadac07ee78eaf330c1 are affected. Installations of the open‑source platform from the WWBN vendor community that have not incorporatedBN AVideo in the vendor catalogue.
Risk and Exploitability
The CVSS base score of 6.9 indicates moderate impact. The EPSS score of <1% suggests a very low probability of exploitation, and the vulnerability has not been recorded in the CISA KEV catalog. Attackers can trigger endpoint over the network; once reached, the service returns the user ID and ad URLs without any authentication. The lack of authorization makes the data available to unauthenticated actors, thereby compromising confidentiality of user identifiers.
OpenCVE Enrichment