Impact
WWBN AVideo fails to verify user permissions in the Bookmark plugin’s getBookmarks.json.php endpoint. An unauthenticated attacker can request the endpoint for videos that are protected by passwords. This flaw allows the disclosure of sensitive metadata without any authentication or password verification, exposing information that could aid further attacks or breach confidentiality.
Affected Systems
The vulnerability affects WWBN AVideo, specifically the commit c3edcc274c389816d434acadac07ee78eaf330c1; no precise version numbers are listed, but the flaw exists in any release that incorporates this commit until a security fix is applied.
Risk and Exploitability
The CVSS score of 6.9 indicates moderate severity. The EPSS score is below 1 percent, indicating a low probability of exploitation, and the vulnerability is not listed in CISA’s KEV catalog. Based on the description, it is inferred that the attack surface is network‑based; an off‑site attacker can simply issue a GET request to the exposed endpoint and retrieve the data without any pre‑authentications. The lack of checks makes the exploitation straightforward and likely to be successful if applicable configurations are enabled.
OpenCVE Enrichment