Impact
An authorization check is missing in the API like endpoint of AVideo versions up to 29.0, allowing logged‑in users to send like or dislike requests for videos that are password‑protected or restricted to certain groups. This flaw lets an attacker inflate or deflate vote counts on content they cannot view, undermining the integrity of the platform’s metrics and possibly influencing recommendations or rankings.
Affected Systems
The vulnerability affects the AVideo application developed by WWBN. All releases up to version 29.0, specifically commit c3edcc274c389816d434acadac07ee78eaf330c1, are impacted. No other vendors or product lines are listed.
Risk and Exploitability
The flaw carries a CVSS score of 5.3, indicating moderate severity. The EPSS score is below 1%, suggesting a very low probability of widespread exploitation, and the vulnerability is not included in the CISA KEV catalog. The likely attack vector requires the actor to be authenticated against the system, as the API call uses the user’s session. Once authenticated, an attacker can execute the request by calling the set.json.php endpoint with appropriate APIName parameters to manipulate votes on restricted videos. The impact is confined to vote manipulation; it does not expose user data or allow arbitrary code execution.
OpenCVE Enrichment