
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-35449 is an unauthenticated information disclosure vulnerability in WWBN AVideo affecting all versions up to and including 26.0. The install/test.php diagnostic script has its CLI-only access guard disabled — the die() statement is commented out — leaving the script accessible via HTTP after installation. This exposes video viewer statistics including IP addresses, session IDs, and user agents to any unauthenticated visitor. Disclosed on April 2, 2026 by aisafe.io and published to the GitHub Advisory Database on April 4, 2026, it carries a CVSS v3.1 base score of 5.3 (Medium) (GitHub Advisory, AVideo Advisory).
The root cause is CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor). In install/test.php lines 5–7, the intended CLI-only guard if (!isCommandLineInterface()) { return die('Command Line only'); } has its die() call commented out, allowing HTTP access. The script additionally sets error_reporting(E_ALL) and ini_set('display_errors', '1'), then calls VideoStatistic::getLastStatistics() and outputs results via var_dump(), exposing a VideoStatistic object containing ip, session_id, user_agent, users_id, and JSON metadata. The install/ directory's .htaccess only disables directory listing (Options -Indexes) and does not block direct access to individual PHP files, so no additional server-side controls prevent exploitation (GitHub Advisory).
Successful exploitation allows any unauthenticated remote attacker to retrieve viewer IP addresses (constituting PII under GDPR), session identifiers, and user agents for any video ID by supplying a videos_id parameter. The display_errors=1 setting additionally leaks internal server filesystem paths in PHP warnings, which could aid further reconnaissance. There is no integrity or availability impact; the risk is limited to confidentiality of viewer data and server path disclosure (AVideo Advisory).
A proof-of-concept exploit is publicly available in the GitHub Security Advisory, consisting of a simple curl command requiring no authentication, credentials, or special tooling. The vulnerability has been confirmed accessible on live AVideo instances returning HTTP 200. As of the time of reporting, there is no evidence of active in-the-wild exploitation, no known threat actor attribution, and the CVE is not listed in the CISA KEV catalog. The EPSS score is approximately 0.028% (0.000280), indicating a low near-term exploitation probability (AVideo Advisory).
https://<target>/install/test.php to confirm the script returns HTTP 200 rather than a CLI-only error.videos_id parameter to retrieve viewer data:curl "https://your-avideo-instance.com/install/test.php?videos_id=1"var_dump() output will contain a VideoStatistic object with fields including ip (viewer IP address), session_id, user_agent, users_id, and JSON metadata.videos_id values to enumerate statistics for multiple videos and collect PII across the platform./install/test.php with a videos_id query parameter from external or unexpected IP addresses; high-frequency enumeration of this endpoint with incrementing videos_id values.GET /install/test.php?videos_id=<N> returning HTTP 200 from unauthenticated clients; PHP error logs showing verbose output or warnings triggered by malformed parameters.install/test.php with the die() statement commented out (lines 5–7) on a production AVideo instance post-installation (AVideo Advisory).No patched version of AVideo has been released as of the advisory publication date; the advisory lists "None" for patched versions. The recommended immediate fix is to uncomment the CLI guard in install/test.php line 6, restoring: if (!isCommandLineInterface()) { return die('Command Line only'); }. As additional workarounds, administrators should restrict HTTP access to the install/ directory via web server configuration (e.g., deny all external access in Apache/Nginx), or remove the install/ directory entirely from production deployments. Setting display_errors = Off in php.ini will also prevent filesystem path leakage (AVideo Advisory, GitHub Advisory).
The vulnerability was discovered and reported by aisafe.io and published by DanielnetoDotCom to the WWBN/AVideo repository. Coverage has appeared on vulnerability aggregation platforms including VulDB, CVEFeed, and Infinit Security, with the latter publishing a dedicated write-up. No significant vendor statement beyond the advisory itself, nor notable researcher commentary or social media discussion, has been observed (GitHub Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."