Impact
AVideo versions up to 29.0 lack proper authorization in the set_api_comment function, allowing authenticated users to post comments on videos that are password‑protected or restricted to specific groups. The vulnerability permits the addition of unauthorized comments without granting viewing rights, effectively enabling users to modify the state of restricted content. This flaw aligns with the Common Weakness Enumeration CWE‑862, which describes missing authorization checks.
Affected Systems
The vulnerability affects the WWBN AVideo platform, specifically all releases through version 29.0, identified by the commit hash c3edcc274c389816d434acadac07ee78eaf330c1. Administrators of installations using any of these releases should consider the affected software component.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate severity flaw. The EPSS score of less than 1 % suggests that, at present, the probability of exploitation is very low. The vulnerability remains listed as not in the CISA KEV catalog. Exploitation requires an authenticated session and the ability to issue POST requests to the comment API endpoint with arbitrary video identifiers. In practice, the attacker can simply supply the ID of a protected video to create a comment, bypassing the intended access control.
OpenCVE Enrichment