Impact
WWBN AVideo contains an access‑control flaw that allows an authenticated user to submit like requests via the like.json.php endpoint without first verifying that the user has permission to view the target video. The flaw is identified as CWE-862. As a result, users can increment the like counter for password‑protected or group‑restricted videos, potentially manipulating popularity metrics and indirectly confirming the existence of protected content.
Affected Systems
The vulnerability affects all installations of WWBN AVideo for which the like.json.php endpoint does not enforce permission checks. No specific version or build information to any instance that has not applied the corrections documented in the advisory references.
Risk and Exploitability
The CVE has a medium severity range, and the EPSS score of < 1 % indicates a very low probability of exploitation. The vulnerability is not listed in CISA’s KEV catalog. Likely attackers are authenticated web users capable of sending HTTP POST requests to like.json.php; no additional privileges are required beyond an attacker to increment likes on videos they cannot access, thereby bypassing intended access controls.
OpenCVE Enrichment