CyberRota Analysis
AI-GeneratedThe vulnerability in WWBN AVideo allows unauthenticated users to access sensitive user records, including password hashes and session identifiers, through the videoViewsInfo endpoint when a hash parameter is supplied. This critical flaw enables attackers to hijack viewer sessions, potentially compromising administrator accounts and exposing personal data of all users. Organizations utilizing AVideo should prioritize immediate remediation to protect against unauthorized access and data breaches.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
WWBN AVideo contains a broken access control vulnerability in videoViewsInfo endpoints that returns complete user records including password hashes, recovery tokens, and live session identifiers to unauthenticated callers when a hash parameter is provided. Attackers can use the disclosed session identifier to hijack viewer sessions, including administrator accounts, and obtain sensitive personal data for all video viewers.