Impact
WWBN AVideo does not enforce watch‑permissions when a user calls the add‑video endpoint for a playlist. An authenticated attacker can supply any video identifier and the identifier of a playlist they own, causing a password‑protected video to appear in that playlist. The flaw is a missing authorization weakness (CWE‑862) and allows the attacker to add videos to playlists that they cannot normally view.
Affected Systems
The vulnerability affects the WWBN AVideo application, specifically the playListAddVideo.json.php endpoint introduced in the commit c3edcc274c389816d434acadac07ee78eaf330c1. All users running this or earlier versions are impacted; upgrading to a release that restores the authorization check resolves the issue.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity. The EPSS score of < 1% indicates a low probability of exploitation. The vulnerability is not included in the CISA KEV catalog, suggesting no known large‑scale exploited deployments. Attack requires an authenticated session and invocation of the endpoint, meaning unauthenticated users cannot exploit it directly. Environments that allow users to add when protected videos can be exposed to additional viewers. Monitoring and timely patching are advised to mitigate further exposure.
OpenCVE Enrichment