Description
AVideo through 29.0 (commit c3edcc274c389816d434acadac07ee78eaf330c1) fails to validate video access permissions in the API like endpoint, allowing logged-in users to vote on password-protected and group-restricted videos. Attackers can submit like and dislike requests to increment vote counters on videos they cannot watch by calling the set.json.php endpoint with APIName parameters.
Published: 2026-09-16
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized vote manipulation
Action: Apply Patch
AI Analysis

Impact

An authorization check is missing in the API like endpoint of AVideo versions up to 29.0, allowing logged‑in users to send like or dislike requests for videos that are password‑protected or restricted to certain groups. This flaw lets an attacker inflate or deflate vote counts on content they cannot view, undermining the integrity of the platform’s metrics and possibly influencing recommendations or rankings.

Affected Systems

The vulnerability affects the AVideo application developed by WWBN. All releases up to version 29.0, specifically commit c3edcc274c389816d434acadac07ee78eaf330c1, are impacted. No other vendors or product lines are listed.

Risk and Exploitability

The flaw carries a CVSS score of 5.3, indicating moderate severity. The EPSS score is below 1%, suggesting a very low probability of widespread exploitation, and the vulnerability is not included in the CISA KEV catalog. The likely attack vector requires the actor to be authenticated against the system, as the API call uses the user’s session. Once authenticated, an attacker can execute the request by calling the set.json.php endpoint with appropriate APIName parameters to manipulate votes on restricted videos. The impact is confined to vote manipulation; it does not expose user data or allow arbitrary code execution.

Generated by OpenCVE AI on September 18, 2026 at 05:23 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update AVideo to a version newer than 29.0 that includes the authorization fix
  • Configure the application to reject like or dislike API calls for videos with access restrictions, ensuring that only authorized viewers can vote
  • Implement role‑based access controls in the API layer to validate user permissions before processing like/dislike requests

Generated by OpenCVE AI on September 18, 2026 at 05:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 02:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
Description AVideo through 29.0 (commit c3edcc274c389816d434acadac07ee78eaf330c1) fails to validate video access permissions in the API like endpoint, allowing logged-in users to vote on password-protected and group-restricted videos. Attackers can submit like and dislike requests to increment vote counters on videos they cannot watch by calling the set.json.php endpoint with APIName parameters.
Title AVideo through 29.0 Missing Authorization Check via API Like Endpoint
First Time appeared Wwbn
Wwbn avideo
Weaknesses CWE-862
CPEs cpe:2.3:a:wwbn:avideo:*:*:*:*:*:*:*:*
Vendors & Products Wwbn
Wwbn avideo
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-19T02:03:35.521Z

Reserved: 2026-09-16T13:47:20.118Z

Link: CVE-2026-92585

cve-icon Vulnrichment

Updated: 2026-09-19T02:03:22.692Z

cve-icon NVD

Status : Deferred

Published: 2026-09-16T22:18:29.027

Modified: 2026-09-22T20:43:58.793

Link: CVE-2026-92585

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T06:30:05Z

Weaknesses