Impact
WWBN AVideo fails to verify user permissions in the Bookmark plugin’s getBookmarks.json.php endpoint. An unauthenticated attacker can request the endpoint with a video identifier and obtain chapter names for videos that are protected by passwords. This flaw allows the disclosure of sensitive metadata without any authentication or password verification, exposing information that could aid further attacks or breach confidentiality.
Affected Systems
The vulnerability affects the WWBN AVideo application, specifically commit c3edcc274c389816d434acadac07ee78eaf330c1. No precise version numbers are listed, but the bug is present in any release that includes this commit until a security fix is applied.
Risk and Exploitability
The CVSS score of 6.9 indicates moderate severity. With no EPSS data available and the vulnerability not yet included in CISA’s KEV catalog, the risk remains primarily theoretical but still meaningful. The attack surface is network‑based; an off‑site attacker can simply issue a GET request to the exposed endpoint and retrieve the data without any pre‑authentications. The lack of checks makes the exploitation straightforward and likely to be successful if applicable configurations are enabled.
OpenCVE Enrichment