Executive brief
AVideo, a video sharing platform, contains a security flaw that allows anyone on the internet to download a complete list of registered users without logging in. This list includes usernames, display names, profile photos, and account status. Attackers can use this information to conduct targeted phishing attacks or attempt to break into user accounts using stolen passwords.
Technical details
The vulnerability exists in `objects/users.json.php` due to two distinct root causes. First, the `isCompany` request parameter triggers a logic branch that sets `$ignoreAdmin = true`, effectively bypassing the administrative permission checks in `User::getAllUsers()` and `User::getTotalUsers()`. Second, the `users_id` parameter allows direct calls to `User::getUserFromID()` without any authentication or authorization checks. An unauthenticated attacker can exploit these paths to leak user IDs, display names, channel URLs, and profile images. The endpoint is also explicitly excluded from CSRF and origin protections in the application's security configuration, and the `rowCount` parameter is unbounded, allowing for bulk data extraction in a single request.
Affected products
- WWBN AVideo (formerly YouPHPTube) <= 29.0
Timeline
- 2026-05-05: advisory: GHSA-6rvw-7p8v-mjfq published