Impact
The vulnerability resides in WWBN AVideo’s ImageGallery list.json.php endpoint, where the application fails to validate user permissions, enabling an unauthenticated user to read the list of filenames and URLs for galleries. This is an instance of CWE‑200 (Information Exposure) and results in a confidentiality impact, exposing the location of private image files that were intended to be protected.
Affected Systems
Any deployment of WWBN AVideo before commit c3edcc274c389816d434acadac07ee78eaf330c1 that exposes the ImageGallery list.json.php endpoint to the public web is affected. This includes installations that have not applied the patch for the missing authorization check.
Risk and Exploitability
The CVSS score of 6.9 indicates a moderate to high severity, and the EPSS score of less than 1% suggests a low probability of exploitation. The vulnerability is not listed in the CISA KEV catalogue. Attackers can reach the compromised endpoint over the web, retrieve file paths and URLs, representing a direct confidentiality breach for any gallery that was intended to be password‑protected.
OpenCVE Enrichment