PT-2026-28623 · Avideo · Avideo
CVSS v3.1
5.3
Média
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
AVideo versions up to and including 26.0
Description
AVideo is an open source video platform. The
get api video file and get api video API endpoints do not verify video passwords for password-protected videos. This allows an unauthenticated attacker to retrieve direct playback URLs for any password-protected video by directly calling the API. The normal web playback flow enforces password checks via the CustomizeUser::getModeYouTube() hook, but this enforcement is absent from the API code path. The issue is addressed by commit be344206f2f461c034ad2f1c5d8212dd8a52b8c7.Recommendations
Update AVideo to a version later than 26.0.
Exploit
Correção
Missing Authorization
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Avideo