PT-2026-27187 · Avideo · Avideo

Restriction

·

Publicado

2026-03-23

·

Atualizado

2026-03-25

·

CVE-2026-33685

CVSS v3.1

5.3

Média

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions AVideo versions prior to 26.1
Description AVideo is an open source video platform. Versions up to and including 26.0 lack authentication and authorization checks on the plugin/AD Server/reports.json.php endpoint. This allows unauthenticated attackers to extract ad campaign analytics data, including video titles, user channel names, user IDs, ad campaign names, and impression/click counts. The HTML counterpart (reports.php) and CSV export (getCSV.php) correctly enforce User::isAdmin(), but the JSON API was left unprotected.
Recommendations Update AVideo to version 26.1 or later.

Exploit

Correção

Missing Authorization

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-33685
GHSA-J36M-74G2-7M95

Produtos afetados

Avideo