Impact
The flaw occurs because the system fails to validate playlist ownership before returning scheduling data. Either unauthenticated or canStream users can query the endpoints and receive schedule names, descriptions, timestamps, and playlist identifiers that should be protected.
Affected Systems
Affected installations of WWBN AVideo that include the Playlists_schedules/list.json.php or Live/calendar.json.php endpoints may be vulnerable. The vulnerability is present in the product as a missing ownership check; however, no specific affected-version details are available from the advisory.
Risk and Exploitability
The CVSS score of 5.3 indicates medium severity, while an EPSS score below 1% suggests low exploitation probability. The lack of authentication and a straightforward query path make it relatively easy for unauthenticated users to abuse the flaw. The vulnerability is not listed in the CISA KEV catalog, but the widespread availability of the vulnerable endpoints makes it a notable risk for any environment running WWBN AVideo.
OpenCVE Enrichment