Information Exposure in AVideo Affects User Privacy
CVE-2026-56380
6.9MEDIUM
What is CVE-2026-56380?
AVideo has a vulnerability in the feed/index.php file that permits unauthorized attackers to collect the email addresses of channel owners. By inputting a public channel name parameter, these attackers can expose sensitive information stored in the itunes:email and itunes:author RSS elements. This flaw allows malicious individuals to enumerate creator email addresses by cycling through public channel names, facilitating potential phishing campaigns and account takeover attempts.
Affected Version(s)
AVideo 0 <= 9c39d8c8b4c1f75540788d6b391740852ceb0732
