important · Edge — Media
An unauthenticated AVideo endpoint is reported to expose live sessions and permit administrator-session hijacking.
Affects
WWBN AVideo, a self-hosted web platform for publishing and streaming video.
The CNA says an anonymous caller can supply the hash parameter to videoViewsInfo and receive user records containing password hashes, recovery tokens and live session identifiers.
Detail and 2 sources
Replaying an administrator's live identifier reportedly inherits the administrator session, but no public reproduction or upstream fix was located.
Chain to watch
Call videoViewsInfo with the hash parameter without authentication→↓Obtain live session identifiers from returned user records→↓Replay an administrator identifier and inherit the session→↓The endpoint behavior and fixed version lack independent upstream or reproduction evidence.
Unverified chainReproduce the endpoint against a stock AVideo release and identify the correcting code change.