Impact
The vulnerability allows attackers to authenticate as any user by submitting the stored password hash directly to login endpoints, bypassing password verification. Two code paths, loginFromRequest() and encryptPasswordVerify(), accept the hash as a valid credential. Based on the description, the attacker can impersonate any user, potentially including accounts with administrative rights. This flaw is classified as CWE‑287 with a CVSS score of 9.2.
Affected Systems
WWBN AVideo, versions 29.0 and earlier. All installs of AVideo through release 29.0 are vulnerable.
Risk and Exploitability
The CVSS score of 9.2 renders the vulnerability critical. The EPSS score is below 1 %, indicating a low probability of exploitation at this time, and the issue is not listed in CISA’s KEV catalog. Based on the description, the attacker would need to have access to the stored password hash. No additional conditions are stated, so the flaw can be leveraged without further prerequisites.
OpenCVE Enrichment