PT-2025-51874 · Avideo · Avideo

·

CVE-2025-34441

·

Published

2025-12-17

·

Updated

2025-12-21

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions AVideo versions prior to 20.1
Description AVideo versions prior to 20.1 have an issue where sensitive user information is exposed through an unauthenticated public API endpoint. The responses from this endpoint include emails, usernames, administrative status, and last login times, which could allow for user enumeration and privacy violations. The affected API endpoint allows access to this information without requiring authentication.
Recommendations Update AVideo to version 20.1 or later.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-34441

Affected Products

Avideo