Impact
WWBN AVideo's TopMenu plugin exposes a /plugin/TopMenu/menus.json.php endpoint that does not enforce authentication. An unauthenticated attacker can issue a simple GET request to that URL and receive a JSON payload containing all menu items, including inactive and admin‑only entries that are normally hidden from the public interface. This constitutes an information disclosure vulnerability (CWE‑200) that could reveal internal application structure or privileged actions to the attacker.
Affected Systems
All installations of WWBN AVideo that include the TopMenu plugin are affected. The CVE statement does not provide a specific version range, so any release that still ships the unauthenticated endpoint is vulnerable. Administrators should assume the endpoint is exposed until the vendor.
Risk and Exploitability
The flaw carries a CVSS score of 6.9, indicating moderate severity. The EPSS score of less than 1% suggests a low but non‑zero likelihood of exploitation in the wild, and it is not currently listed in the CISA KEV catalog. Attackers can exploit the vulnerability by sending an unauthenticated HTTP GET request to the endpoint from any location that can reach the web server; no special network configuration is required. The path to exploitation is straightforward, and the weakness does not require user interaction or administrative privileges.
OpenCVE Enrichment