PT-2026-94102 · Avideo · Avideo
CVSS v4.0
5.3
Medium
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
AVideo versions prior to 29.0 (commit c3edcc274c389816d434acadac07ee78eaf330c1)
Description
Logged-in users can vote on password-protected and group-restricted videos because the system fails to validate video access permissions in the API like endpoint. This allows attackers to increment vote counters on videos they are not authorized to watch by calling the 'set.json.php' endpoint using
APIName parameters.Recommendations
Update to a version later than 29.0 (commit c3edcc274c389816d434acadac07ee78eaf330c1).
Exploit
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Avideo