Impact
WWBN AVideo has a missing authorization check in the remindMe.json.php endpoint. Authenticated that they otherwise cannot access. The generated email job contains the schedule title, allowing the attacker to discover the title of a private schedule. This flaw is a classic missing authorization weakness (CWE-639).
Affected Systems
The vulnerability exists in WWBN AVideo releases that include commit c3edcc274c389816d434acadac07ee78eaf330c. Any release built from that commit onward is potentially vulnerable until the authorization check is restored.
Risk and Exploitability
The CVSS score is 5.3, and the vulnerability is not listed in the CISA KEV catalog. EPSS data is not available. Once authenticated, exploitation is trivial: an attacker can freely create reminders for private schedules and learn the schedule title from the email job. The risk is elevated for compromised or default accounts.
OpenCVE Enrichment