Executive brief
AVideo, an open-source video platform, contains a flaw that allows registered users with upload permissions to view file names and locations across the entire server. By manipulating folder paths, an attacker can discover private or premium video content and map out the server's internal directory structure. This could lead to the exposure of sensitive media files and provide information useful for further attacks.
Technical details
A path traversal vulnerability exists in the `listFiles.json.php` endpoint of AVideo due to insufficient validation of the `path` POST parameter. The application passes this user-supplied path directly to the PHP `glob()` function without enforcing a base directory restriction or using `realpath()` for normalization. An authenticated user with `canUpload` privileges can provide absolute paths to traverse the filesystem and list all `.mp4` files readable by the web server process. This results in the disclosure of full absolute filesystem paths for sensitive, private, or premium media content, as well as general server directory structure. The issue is addressed in version 26.0.
Affected products
- WWBN AVideo <= 25.0
Timeline
- 2026-03-18: disclosed
- 2026-03-19: advisory
- 2026-03-19: patched