PT-2026-86415 · Avideo · Avideo
CVSS v4.0
9.3
Critical
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
AVideo (affected versions not specified)
Description
Broken access control in the 'videoViewsInfo' endpoint allows unauthenticated callers to retrieve complete user records when a
hash parameter is provided. The exposed data includes password hashes, recovery tokens, and live session identifiers. This can lead to the hijacking of viewer sessions, including those of administrator accounts, and the unauthorized acquisition of sensitive personal data for all video viewers.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Avideo