Impact
The vulnerability in WWBN AVideo, identified by commit c3edcc274c389816d434acadac07ee78eaf330c1, allows attackers to read private playlist schedule metadata through the Playlists_schedules/list.json.php and Live/calendar.json.php endpoints. The flaw arises because ownership checks are omitted, enabling authenticated users with canStream privileges or even unauthenticated users to retrieve schedule names, descriptions, timestamps, and playlist identifiers of playlists they do not own. This constitutes that permits unintended disclosure of sensitive scheduling information, potentially aiding further attacks.
Affected Systems
Affected are installations of WWBN AVideo that include the Playlists_schedules/list.json.php or Live/calendar.json.php endpoints. No specific version constraints are provided in the CVE entry, so all publicly released builds may be vulnerable until a patch is applied.
Risk and Exploitability
The CVSS score of 5.3 indicates a medium severity vulnerability. Because exact exploitation likelihood is uncertain, but the lack of authentication requirements and the straightforward query path suggest that unauthorized users can easily abuse the flaw. The vulnerability is not currently listed in the CISA KEV catalog, however the wide availability of the vulnerable endpoints makes it a notable risk for any environment running WWBN AVideo.
OpenCVE Enrichment