PT-2026-83080 · Wwbn · Avideo
CVSS v4.0
6.9
Medium
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
WWBN AVideo versions prior to 30.1
Description
Authentication is not enforced on the 'report4.json.php' and 'report4.1.json.php' endpoints. This allows unauthenticated users to send GET requests to these endpoints to retrieve daily and cumulative user registration statistics without requiring a session or authorization.
Recommendations
Update to a version later than 30.0.
Restrict access to the 'report4.json.php' and 'report4.1.json.php' endpoints as a temporary mitigation measure.
Exploit
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Avideo