Impact
WWBN AVideo does not perform proper authorization on the videosAndroid.json.php endpoint, permitting unauthenticated users to query password‑protected videos and receive detailed metadata. The exposed data includes the owner’s email, last login timestamp, file name, and hash identifier, providing an attacker with actionable information that could be leveraged for phishing, credential harvesting, or targeted profiling.
Affected Systems
This vulnerability affects installations of the WWBN AVideo platform that include the vulnerable codebase identified by commit c3edcc274c389816d434acadac07ee78eaf330c1. Because that commit or earlier are potentially impacted until the authorization fix is applied.
Risk and Exploitability
The CVSS score of 6.9 indicates a medium severity vulnerability. EPSS information is not available, offering no indication of current exploitation likelihood, and the flaw is absent from the CISA KEV catalog. The likely attack vector is a simple unauthenticated HTTP GET to the endpoint, which can be performed by any network entity that can reach the application server. An attacker can immediately enumerate video metadata without authentication, resulting in a real risk to user privacy and potential future exploitation.
OpenCVE Enrichment