Impact
WWBN AVideo contains a missing‑authorization flaw in the playlistsFromUser.json.php endpoint that permits any unauthenticated user to download the private Favorite and Watch Later playlists of any account by supplying that account’s identifier. The vulnerability is a CWE‑200 confidentiality issue that arises from the lack of requester validation and from improper cache keying that merges requests across distinct user contexts, thereby leaking confidential user data.
Affected Systems
All installations of WWBN AVideo that include the code from commit c3edcc274c389816d434acadac07ee78eaf330c1 are affected. Administrators should verify that their deployment is at least this commit or newer, as only releases that incorporate the missing‑authorization fix in playlistsFromUser.json.php address the issue.
Risk and Exploitability
The CVSS score of 6.9 classifies the vulnerability as moderately severe, while the EPSS score of less than 1% indicates a low but non‑zero chance of exploitation. It is not listed in CISA’s KEV catalog. The likely attack vector is a remote, unauthenticated HTTP request to the publicly reachable playlistsFromUser.json.php endpoint. Based on the description, it is inferred that an attacker sends a crafted request such as /playlistsFromUser.json.php?userId=<target>, bypassing any authentication and retrieving the target’s private playlists.
OpenCVE Enrichment