Impact
The AVideo API endpoint get_api_video contains a broken access control flaw in the clean_title branch that allows an unauthenticated user to query videos by their public slug. This flaw returns video entries that are restricted to specific user groups, but it also leaks owner Personally Identifiable Information including email, phone number, mailing address, birth date, and administrative status. The weakness is classified as CWE‑639, representing an authorization bypass through a user‑controlled key.
Affected Systems
The vulnerability affects all releases of WWBN AVideo up to and including version 29.0. The affected component is the server side API that processes the get_api_video request using clean_title parameters.
Risk and Exploitability
With a CVSS score of 8.7, the vulnerability is considered high severity. The EPSS score is less than 1 %, suggesting a low likelihood of exploitation at this time, and the issue is not listed in CISA’s KEV catalog. Because the endpoint is publicly accessible, an attacker needs only to know or guess a video slug to trigger the flaw and retrieve the exposed PII. No authentication or special privileges are required for exploitation, making the attack vector straightforward via standard HTTP requests.
OpenCVE Enrichment