| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-g2mg-cgr6-vmv7 | AVideo: Missing Authentication in CreatePlugin list.json.php Template Affects 21 Endpoints |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Wed, 01 Apr 2026 23:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Wwbn
Wwbn avideo |
|
| CPEs | cpe:2.3:a:wwbn:avideo:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Wwbn
Wwbn avideo |
|
| Metrics |
ssvc
|
Wed, 01 Apr 2026 02:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | WWBN AVideo is an open source video platform. In versions 26.0 and prior, the AVideo CreatePlugin template for list.json.php does not include any authentication or authorization check. While the companion templates add.json.php and delete.json.php both require admin privileges, the list.json.php template was shipped without this guard. Every plugin that uses the CreatePlugin code generator inherits this omission, resulting in 21 unauthenticated data listing endpoints across the platform. These endpoints expose sensitive data including user PII, payment transaction logs, IP addresses, user agents, and internal system records. At time of publication, there are no publicly available patches. | |
| Title | AVideo: Missing Authentication in CreatePlugin list.json.php Template Affects 21 Endpoints | |
| Weaknesses | CWE-306 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-04-01T13:38:51.374Z
Reserved: 2026-03-30T18:41:20.754Z
Link: CVE-2026-34732
Updated: 2026-04-01T13:38:41.764Z
Status : Analyzed
Published: 2026-03-31T21:16:31.910
Modified: 2026-04-01T18:38:07.460
Link: CVE-2026-34732
No data.
OpenCVE Enrichment
No data.
Github GHSA