Skip to finding
important · Edge — Media

An unauthenticated AVideo endpoint is reported to expose live sessions and permit administrator-session hijacking.

Affects

WWBN AVideo, a self-hosted web platform for publishing and streaming video.

The CNA says an anonymous caller can supply the hash parameter to videoViewsInfo and receive user records containing password hashes, recovery tokens and live session identifiers.

Detail and 2 sources

Replaying an administrator's live identifier reportedly inherits the administrator session, but no public reproduction or upstream fix was located.

Chain to watch
Call videoViewsInfo with the hash parameter without authentication→↓Obtain live session identifiers from returned user records→↓Replay an administrator identifier and inherit the session→↓The endpoint behavior and fixed version lack independent upstream or reproduction evidence.
Unverified chainReproduce the endpoint against a stock AVideo release and identify the correcting code change.
Share this finding
Get it by email

The same brief, every morning. One email a day, nothing else.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Sunday, September 6, 2026