AVideo versions prior to 20.1 expose sensitive user information through an unauthenticated public API endpoint. Responses include emails, usernames, administrative status, and last login times, enabling user enumeration and privacy violations.
References
Configurations
History
No history.
Information
Published : 2025-12-17 20:15
Updated : 2025-12-19 19:15
NVD link : CVE-2025-34441
Mitre link : CVE-2025-34441
CVE.ORG link : CVE-2025-34441
JSON object : View
Products Affected
wwbn
- avideo
CWE
CWE-359
Exposure of Private Personal Information to an Unauthorized Actor
