WWBN AVideo is an open source video platform. In versions 26.0 and prior, the install/test.php diagnostic script has its CLI-only access guard disabled by commenting out the die() statement. The script remains accessible via HTTP after installation, exposing video viewer statistics including IP addresses, session IDs, and user agents to unauthenticated visitors.
Project Subscriptions
No data.
Advisories
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-hg8q-8wqr-35xx | AVideo: Unauthenticated Information Disclosure via Disabled CLI Guard in install/test.php |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Tue, 07 Apr 2026 00:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | WWBN AVideo is an open source video platform. In versions 26.0 and prior, the install/test.php diagnostic script has its CLI-only access guard disabled by commenting out the die() statement. The script remains accessible via HTTP after installation, exposing video viewer statistics including IP addresses, session IDs, and user agents to unauthenticated visitors. | |
| Title | WWBN AVideo has Unauthenticated Information Disclosure via Disabled CLI Guard in install/test.php | |
| Weaknesses | CWE-200 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-04-06T21:46:07.363Z
Reserved: 2026-04-02T19:25:52.192Z
Link: CVE-2026-35449
No data.
Status : Received
Published: 2026-04-06T22:16:23.310
Modified: 2026-04-06T22:16:23.310
Link: CVE-2026-35449
No data.
OpenCVE Enrichment
No data.
Weaknesses
Github GHSA