WWBN AVideo is an open source video platform. In versions 26.0 and prior, the install/test.php diagnostic script has its CLI-only access guard disabled by commenting out the die() statement. The script remains accessible via HTTP after installation, exposing video viewer statistics including IP addresses, session IDs, and user agents to unauthenticated visitors.
Advisories
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-hg8q-8wqr-35xx | AVideo: Unauthenticated Information Disclosure via Disabled CLI Guard in install/test.php |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Tue, 07 Apr 2026 09:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Wwbn
Wwbn avideo |
|
| Vendors & Products |
Wwbn
Wwbn avideo |
Tue, 07 Apr 2026 00:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | WWBN AVideo is an open source video platform. In versions 26.0 and prior, the install/test.php diagnostic script has its CLI-only access guard disabled by commenting out the die() statement. The script remains accessible via HTTP after installation, exposing video viewer statistics including IP addresses, session IDs, and user agents to unauthenticated visitors. | |
| Title | WWBN AVideo has Unauthenticated Information Disclosure via Disabled CLI Guard in install/test.php | |
| Weaknesses | CWE-200 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-04-07T13:28:55.133Z
Reserved: 2026-04-02T19:25:52.192Z
Link: CVE-2026-35449
No data.
Status : Undergoing Analysis
Published: 2026-04-06T22:16:23.310
Modified: 2026-04-07T14:16:23.267
Link: CVE-2026-35449
No data.
OpenCVE Enrichment
Updated: 2026-04-07T09:36:37Z
Weaknesses
Github GHSA