Stats Digest Feeds
โ† Back to all CVEs

CVE-2026-43885

UNKNOWN NVD
CVSS Score 0
Severity UNKNOWN
Published May 11, 2026
Vendor unknown

Description

WWBN AVideo is an open source video platform. In versions up to and including 29.0, an unauthenticated user can read APISecret from objects/plugins.json.php and use it to call protected API endpoints (e.g. users_list) without logging in. Commit 1c36f229d0a103528fb9f64d0a1cc0e1e8f5999b contains an updated fix.

References