Impact
A missing authentication check in the plugin/TopMenu/menuItems.json.php endpoint of WWBN AVideo allows an attacker to send an unauthenticated POST request containing a menuId parameter. The response includes inactive admin menu items that are normally hidden from the public navigation bar. These items expose secret administrative URLs with query parameters that an attacker can use without needing further privileges.
Affected Systems
The vulnerability affects the WWBN as c3edcc274c389816d434acadac07ee78eaf330c1. Earlier commits are not explicitly listed but may also be impacted if the same endpoint continues to lack authentication checks. No specific version range is supplied; all affected installations that expose the vulnerable endpoint are at risk.
Risk and Exploitability
The CVSS base score is 6.9, indicating moderate severity. The EPSS score is less than 1%, showing a very low likelihood of exploitation by current actors. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. Attackers can exploit this weakness remotely by reaching the AVideo server over the network and submitting the malformed POST request. Because no authentication is required, the vulnerability can be used by any adversary who can reach the endpoint.
OpenCVE Enrichment