Information Exposure in AVideo Affects User Privacy
CVE-2026-56380

6.9MEDIUM

Key Information:

Vendor

Wwbn

Status
Vendor
CVE Published:
22 August 2026

What is CVE-2026-56380?

AVideo has a vulnerability in the feed/index.php file that permits unauthorized attackers to collect the email addresses of channel owners. By inputting a public channel name parameter, these attackers can expose sensitive information stored in the itunes:email and itunes:author RSS elements. This flaw allows malicious individuals to enumerate creator email addresses by cycling through public channel names, facilitating potential phishing campaigns and account takeover attempts.

Affected Version(s)

AVideo 0 <= 9c39d8c8b4c1f75540788d6b391740852ceb0732

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

santhreal
.