Impact
The vulnerability is located in the commentAddNew.json.php endpoint of WWBN AVideo and is a CWE-862 Missing Authorization flaw. It occurs because the code does not validate permission to view a video before allowing a comment to be posted. As a result, an authenticated user can send POST requests with a valid session token to add comments on videos that are protected by passwords, granting unauthorized social‑engineering or spam activity on content that the user should not have visibility of.
Affected Systems
The affected product is WWBN AVideo. The commit between c3edcc274c389816d434acadac07ee78eaf330c1 and its successors exposes the flaw. No specific released versions are listed, so any installation that has not incorporated this commit remains vulnerable.
Risk and Exploitability
The CVSS score of 5.3 indicates a medium severity vulnerability. The EPSS score is below 1 %, suggesting a low probability of exploitation at this time. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires an authenticated session, so the attacker must either steal or hijack a user’s session token or convince a user to expose it. Once authenticated, the attacker can add comments to restricted videos, possibly bypassing privacy controls and facilitating social‑engineering or defacement. The attack vector is limited to authenticated POST requests to the commentAddNew.json.php endpoint.
OpenCVE Enrichment