CyberRota Analysis
AI-GeneratedAVideo versions up to 29.0 are vulnerable to an authentication bypass in the epg.json.php endpoint, allowing unauthenticated users to access live-stream keys and private EPG schedules. This vulnerability enables attackers to exploit sequential user or playlist IDs to extract sensitive information, including credentials and server identifiers. Organizations using AVideo should prioritize patching this vulnerability to protect their streaming content and user data from unauthorized access.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
AVideo through 29.0 contains an authentication bypass vulnerability in plugin/PlayLists/epg.json.php that exposes live-stream keys and private EPG schedules to unauthenticated users. Attackers can request the endpoint with sequential user or playlist IDs to retrieve sensitive credentials, server identifiers, and complete programme schedules without authentication.