Impact
WWBN AVideo fails to enforce user‑group restrictions on the Live plugin. Unauthenticated attackers can retrieve restricted live transmission details, including stream keys, titles, descriptions, owner information, and direct HLS playback URLs by accessing the plugin/Live/stats.json.php and plugin/Live/calendar.json.php endpoints. This is an information‑disclosure flaw (CWE‑200) that compromises the confidentiality of live video streams.
Affected Systems
WWBN AVideo for all platforms, versions up to and including 29.0, and any installation using the Live plugin that exposes the plugin/Live/stats.json.php or plugin/Live/calendar.json.php endpoints.
Risk and Exploitability
The CVSS score of 8.7 classifies the vulnerability as high, and the lack of authentication requirements means attackers can exploit it simply by sending HTTP requests to the vulnerable endpoints. The EPSS score of less than 1% indicates a very low but nonzero likelihood of exploitation, and the vulnerability is not listed in KEV. Effective exploitation requires only network access to the server and knowledge of the endpoint URLs.
OpenCVE Enrichment