Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-349p-7f27-qvx8

Опубликовано: 11 фев. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 8.7
CVSS3: 7.5

Описание

AVideo Platform 8.1 contains an information disclosure vulnerability that allows attackers to enumerate user details through the playlistsFromUser.json.php endpoint. Attackers can retrieve sensitive user information including email, password hash, and administrative status by manipulating the users_id parameter.

AVideo Platform 8.1 contains an information disclosure vulnerability that allows attackers to enumerate user details through the playlistsFromUser.json.php endpoint. Attackers can retrieve sensitive user information including email, password hash, and administrative status by manipulating the users_id parameter.

EPSS

Процентиль: 44%
0.00565
Низкий

8.7 High

CVSS4

7.5 High

CVSS3

Дефекты

CWE-359

Связанные уязвимости

CVSS3: 7.5
nvd
6 месяцев назад

AVideo Platform 8.1 contains an information disclosure vulnerability that allows attackers to enumerate user details through the playlistsFromUser.json.php endpoint. Attackers can retrieve sensitive user information including email, password hash, and administrative status by manipulating the users_id parameter.

EPSS

Процентиль: 44%
0.00565
Низкий

8.7 High

CVSS4

7.5 High

CVSS3

Дефекты

CWE-359