Description
AVideo versions prior to 20.1 expose sensitive user information through an unauthenticated public API endpoint. Responses include emails, usernames, administrative status, and last login times, enabling user enumeration and privacy violations.
Problem types
CWE-359 Exposure of Private Personal Information to an Unauthorized Actor
Product status
Any version before 20.1
Credits
Valentin Lobstein (Chocapikk)
References
github.com/WWBN/AVideo/commit/4a53ab2056
github.com/WWBN/AVideo/commit/1416c517e2
www.vulncheck.com/...r-information-disclosure-via-public-api
chocapikk.com/posts/2025/avideo-security-vulnerabilities/
Data based on CVE®. Copyright © 1999-2025, The MITRE Corporation. All rights reserved.