โ† All reports

The WWBN AVideo platform has multiple security vulnerabilities that expose it to potential exploitation by malicious actors.

CybersecurityTechnologyConflictApr 21, 2026score 0.173 posts ยท 0 replies across 1 instances
This thread discusses multiple security vulnerabilities in the WWBN AVideo platform, including insecure file path construction, exposure of commit hashes, and an insecure direct object reference vulnerability. These issues highlight significant security risks in the software's handling of user input and data exposure.

Claims

The WWBN AVideo platform has multiple security vulnerabilities that expose it to potential exploitation by malicious actors.
Parent: CybersecurityEntity: WWBN AVideoImpact: negativeDate: Apr 21, 2026Target: The security of the WWBN AVideo platform

Source posts

@[email protected]
๐Ÿšจ EUVD-2026-24284 ๐Ÿ“Š Score: 6.5/10 (CVSS v3.1) ๐Ÿ“ฆ Product: AVideo ๐Ÿข Vendor: WWBN ๐Ÿ“… Updated: 2026-04-21 ๐Ÿ“ WWBN AVideo is an open source video platform. In versions 29.0 and prior, the endpoint `plugin/Live/view/Live_restreams/list.json.php` contains an Insecure Direct Object Reference (IDOR) vulnerability that allows any authenticated user with streaming permission ... ๐Ÿ”— https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-24284 #cybersecurity #infosec #euvd #cve #vulnerability
0 boosts ยท 0 favs ยท 0 replies ยท Apr 21, 2026
#cybersecurity#infosec#euvd#cve#vulnerability
@[email protected]
๐Ÿšจ EUVD-2026-24286 ๐Ÿ“Š Score: 5.3/10 (CVSS v3.1) ๐Ÿ“ฆ Product: AVideo ๐Ÿข Vendor: WWBN ๐Ÿ“… Updated: 2026-04-21 ๐Ÿ“ WWBN AVideo is an open source video platform. In versions 29.0 and prior, the file `git.json.php` at the web root executes `git log -1` and returns the full output as JSON to any unauthenticated user. This exposes the exact deployed commit hash (enabling version... ๐Ÿ”— https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-24286 #cybersecurity #infosec #euvd #cve #vulnerability
0 boosts ยท 0 favs ยท 0 replies ยท Apr 21, 2026
#cybersecurity#infosec#euvd#cve#vulnerability
@[email protected]
๐Ÿšจ EUVD-2026-24288 ๐Ÿ“Š Score: 8.7/10 (CVSS v3.1) ๐Ÿ“ฆ Product: AVideo ๐Ÿข Vendor: WWBN ๐Ÿ“… Updated: 2026-04-21 ๐Ÿ“ WWBN AVideo is an open source video platform. In versions 29.0 and prior, the locale save endpoint (`locale/save.php`) constructs a file path by directly concatenating `$_POST['flag']` into the path at line 30 without any sanitization. The `$_POST['code']` param... ๐Ÿ”— https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-24288 #cybersecurity #infosec #euvd #cve #vulnerability
0 boosts ยท 0 favs ยท 0 replies ยท Apr 21, 2026
#cybersecurity#infosec#euvd#cve#vulnerability
@[email protected]
๐Ÿšจ EUVD-2026-24485 ๐Ÿ“Š Score: 8.3/10 (CVSS v3.1) ๐Ÿ“ฆ Product: AVideo ๐Ÿข Vendor: WWBN ๐Ÿ“… Updated: 2026-04-21 ๐Ÿ“ WWBN AVideo is an open source video platform. In versions 29.0 and prior, `objects/configurationUpdate.json.php` (also routed via `/updateConfig`) persists dozens of global site settings from `$_POST` but protects the endpoint only with `User::isAdmin()`. It doe... ๐Ÿ”— https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-24485 #cybersecurity #infosec #euvd #cve #vulnerability
1 boosts ยท 0 favs ยท 0 replies ยท Apr 21, 2026
#cybersecurity#infosec#euvd#cve#vulnerability