Impact
WWBN AVideo allows an attacker to request the video_from_program API without any authentication, bypassing ownership checks and exposing the contents of private playlists. The attacker can enumerate playlist names, discover owner identities, and retrieve video titles, including those in password-protected content due to this missing authorization defect (CWE-862). The primary consequence is confidential information disclosure of protected content, potentially enabling further exploitation if additional weaknesses exist.
Affected Systems
The vulnerability affects installations of the WWBN AVideo. All deployed versions that include the unpatched commit c3edcc274c389816d434acadac07ee are vulnerable. No specific version list is provided, so any instance that uses the affected code should be considered at risk.
Risk and Exploitability
This missing authorization flaw (CWE-862) carries a CVSS score of 6.9, indicating moderate severity. EPSS data is not available, so the current empirical exploitation probability is unknown. The vulnerability is not listed in the CISA KEV catalog. Attackers can leverage the open API to gather sensitive information without any user interaction or authentication, making exploitation trivial for automated scanners or malicious actors who discover the endpoint. Because the API returns metadata about private collections, the impact is primarily confidentiality breach with potential for further exploitation if additional weaknesses exist.
OpenCVE Enrichment