AVideo through revision c3edcc274c389816d434acadac07ee78eaf330c1 contains a missing authorization vulnerability in plugin/PlayerSkins/seo.php that allows unauthenticated attackers to access password-protected video sources by calling getSources() without password validation. Attackers can request the seo.php endpoint with a video ID to obtain the direct MP4 URL and read protected media bytes without supplying the configured password.
Metrics
Affected Vendors & Products
References
History
Thu, 10 Sep 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | AVideo through revision c3edcc274c389816d434acadac07ee78eaf330c1 contains a missing authorization vulnerability in plugin/PlayerSkins/seo.php that allows unauthenticated attackers to access password-protected video sources by calling getSources() without password validation. Attackers can request the seo.php endpoint with a video ID to obtain the direct MP4 URL and read protected media bytes without supplying the configured password. | |
| Title | AVideo PlayerSkins seo.php Missing Authorization Password-Protected VOD | |
| First Time appeared |
Wwbn
Wwbn avideo |
|
| Weaknesses | CWE-200 | |
| CPEs | cpe:2.3:a:wwbn:avideo:-:*:*:*:*:*:*:* | |
| Vendors & Products |
Wwbn
Wwbn avideo |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published: 2026-09-10T13:05:28.757Z
Updated: 2026-09-10T13:05:28.757Z
Reserved: 2026-09-10T11:24:26.196Z
Link: CVE-2026-88876
No data.
Status : Deferred
Published: 2026-09-10T14:17:15.877
Modified: 2026-09-10T15:13:07.090
Link: CVE-2026-88876
No data.