Impact
WWBN AVideo’s TopMenu plugin exposes a menus.json.php endpoint that does not validate authentication. When accessed, the endpoint returns a JSON list of all menu items, including those marked inactive or reserved forenticated attacker hidden, potentially revealing administrative controls that could facilitate further exploitation.
Affected Systems
All installations of WWBN AVideo that include the TopMenu plugin are affected, as the CNA did not specify a limited version range. Current releases with the plugin are therefore susceptible until a patch is applied.
Risk and Exploitability
The vulnerability carries a CVSS score of 6.9, indicating moderate severity. No EPSS score is available, and the issue is not listed in the CISA KEV catalog. An attacker can exploit it by simply issuing a GET request to the /plugin/TopMenu/menus.json.php URL over the network, requiring no credentials. The ease of exploitation, coupled with the potential to expose sensitive internal menu structures, makes this a notable risk for sites that expose the endpoint publicly.
OpenCVE Enrichment