Impact
WWBN AVideo has a missing authorization check in the remindMe.json.php endpoint. Authenticated users that otherwise cannot access the content can still create scheduler reminders. The generated email job contains the schedule title, allowing the attacker to discover the title of a private schedule. This flaw is a classic missing authorization weakness (CWE-639).
Affected Systems
The vulnerability exists in WWBN AVideo releases that include commit c3edcc274c389816d434acadac07ee Any release built from that commit onward is potentially vulnerable until the authorization check is restored.
Risk and Exploitability
The CVSS score is 5.3, and the vulnerability is not listed in the CISA KEV catalog. The EPSS score is less than 1%. Once authenticated, exploitation is trivial: an attacker can freely create reminders for private schedules and learn the schedule title from the email job.
OpenCVE Enrichment