CyberRota Analysis
AI-GeneratedThe Brushfire platform's video content streaming application exposes sensitive database path information in user requests, enabling remote, unauthenticated attackers to potentially access user data. This vulnerability poses a medium risk, particularly for organizations utilizing the Brushfire platform for streaming services. Users of this platform should prioritize applying the fix released in February 2026 to mitigate the risk of unauthorized data exposure.
Original NVD Description
The Brushfire platform's video content streaming application (https://online.brushfire.com) exposes database path in requests to users, allowing a remote, unauthenticated attacker to read information about other users. Fixed February 2026.