Impact
The vulnerability in the WWBN AVideo platform occurs at the videoAddViewCount.json.php endpoint, where the system updates view metrics without first verifying that the authenticated user has permission to access the referenced video. Because the request body or query can supply an arbitrary video identifier, an attacker can manipulate the view count and watch‑time statistics for videos they are not allowed to view. This flaw is an authorization bypass (CWE‑862) and does not provide code execution, remote code compromise, or direct data disclosure, but it does undermine the integrity of usage analytics.
Affected Systems
The affected product is WWBN AVideo. The flaw exists in the code base at commit c3edcc274c389816d434acadac07ee78eaf330c1 and is present in any release that has not yet integrated the corrective change referenced by the vendor’s security advisory. No specific version range is listed, so all affected releases before the fix should be considered vulnerable.
Risk and Exploitability
The CVSS score of 5.3 indicates medium severity. The EPSS score of < 1% suggests a low likelihood of exploitation in the wild. The vulnerability is not listed in CISA KEV. An attacker must already be authenticated, and can repeatedly trigger the endpoint with disallowed video identifiers. The principal risk is the integrity of view‑count and watch‑time metrics; the overall threat level remains low due to the limited exploitability and requirement for authentication.
OpenCVE Enrichment