PT-2026-92084 · Wwbn · Avideo
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
WWBN AVideo versions prior to 29.1
Description
Failure to enforce user-group restrictions allows unauthenticated attackers to retrieve restricted live transmission details. This information includes stream keys, titles, descriptions, owner information, and direct HLS (HTTP Live Streaming) playback URLs. The issue occurs when accessing the 'plugin/Live/stats.json.php' and 'plugin/Live/calendar.json.php' endpoints.
Recommendations
Update WWBN AVideo to a version later than 29.0.
Restrict access to the 'plugin/Live/stats.json.php' and 'plugin/Live/calendar.json.php' endpoints to minimize the risk of exploitation.
Exploit
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Avideo