Impact
The vulnerability is a missing authorization check in AVideo’s Scheduler plugin. An attacker can supply a site‑wide daily token to the sendEmail.json.php endpoint and retrieve details of scheduled email jobs, view private live titles and recipient addresses, and trigger emails to be sent. This exposes confidential information and allows unsolicited email dispatches. The weakness aligns with CWE‑862, representing an authorization flaw.
Affected Systems
WWBN AVideo’s Scheduler plugin, all releases before434acadac07ee78eaf330c1. The vulnerability is present in every affected release that has not applied this commit, regardless of exact version numbers. The product is identified as WWBN:AVideo.
Risk and Exploitability
The CVSS score of 8.8 indicates a high severity. The EPSS score of <1% points to a very low, yet non‑zero, probability of exploitation, and the flaw is not listed in CISA KEV. Attackers can obtain the required token by viewing Live pages, and then send HTTP requests to the open endpoint, so exploitation is feasible without special privileges.
OpenCVE Enrichment