Описание
AVideo Platform 8.1 contains an information disclosure vulnerability that allows attackers to enumerate user details through the playlistsFromUser.json.php endpoint. Attackers can retrieve sensitive user information including email, password hash, and administrative status by manipulating the users_id parameter.
Ссылки
- Product
- Product
- ExploitThird Party AdvisoryVDB Entry
- Third Party Advisory
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:wwbn:avideo:8.1:*:*:*:*:*:*:*
EPSS
Процентиль: 44%
0.00565
Низкий
7.5 High
CVSS3
Дефекты
CWE-359
Связанные уязвимости
CVSS3: 7.5
github
6 месяцев назад
AVideo Platform 8.1 contains an information disclosure vulnerability that allows attackers to enumerate user details through the playlistsFromUser.json.php endpoint. Attackers can retrieve sensitive user information including email, password hash, and administrative status by manipulating the users_id parameter.
EPSS
Процентиль: 44%
0.00565
Низкий
7.5 High
CVSS3
Дефекты
CWE-359