CyberRota Analysis
AI-GeneratedAVideo versions prior to 30.0 are vulnerable due to a lack of authentication on the report4.json.php and report4.1.json.php endpoints, enabling unauthorized access to sensitive user registration statistics. This vulnerability allows attackers to exploit the system by sending GET requests to obtain daily and cumulative registration data without needing any authentication. Organizations using AVideo should prioritize patching this issue to protect user data and maintain compliance with privacy regulations.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
WWBN AVideo through version 30.0 fails to enforce authentication on the report4.json.php and report4.1.json.php endpoints, allowing unauthenticated access to user registration statistics. Attackers can send GET requests to these endpoints to retrieve daily and cumulative user-registration counts without any session or authorization.