Impact
The vulnerability is a missing authorization check in AVideo’s Scheduler plugin, allowing attackers to use a site‑wide daily token to interact with the sendEmail.json.php endpoint. This flaw lets attackers enumerate scheduler jobs, read private live titles and email addresses, and trigger email dispatches, resulting in disclosure of confidential data and possible misuse of the emailing feature.
Affected Systems
WWBN AVideo’s Scheduler plugin, versions prior to the commit that fixed the authorization issue (c3edcc274c389816d434acadac07ee78e authorization logic. All affected releases expose the sendEmail.json.php endpoint without requiring proper user authentication or access control.
Risk and Exploitability
The CVSS score of 8.8 indicates a high severity of this flaw. EPSS is not available, so the current exploit probability is unknown, and the vulnerability is not listed in CISA KEV. Attackers are likely to obtain a valid daily token from Live pages to bypass authorization. Because the token can be derived from normal site usage, the required attack vector is web‑based and does not need special privileges, making exploitation relatively straightforward for malicious actors.
OpenCVE Enrichment