Unauthenticated User Enumeration in WWBN AVideo
CVE-2026-45620
5.3MEDIUM
What is CVE-2026-45620?
A security flaw exists in the WWBN AVideo platform that allows unauthenticated users to enumerate existing user accounts. In versions 29.0 and prior, the file objects/mention.json.php lacks proper user authentication checks. This oversight permits attackers to exploit the preg_match validation on the 'term' parameter, leading to unauthorized access to account details by modifying the request. As a result, this vulnerability presents significant risks to the privacy and security of user data, necessitating prompt remediation.
Affected Version(s)
AVideo <= 29.0
