Executive brief
AVideo is a video platform that includes a cryptographic message decryption feature. An unauthenticated endpoint allows anyone on the network to submit encryption keys and encrypted messages for server-side decryption without logging in or providing any credentials. This exposes private keys to server logs and allows attackers to perform unlimited decryption operations, consuming server resources and potentially revealing sensitive key material to anyone with log access.
Technical details
The vulnerability is a missing authentication check in the decryptMessage.json.php endpoint (CWE-306). The endpoint accepts a JSON POST request with three fields: textToDecrypt, privateKeyToDecryptMsg, and keyPassword. The server directly passes these to a decryption function without calling any session validation or User::isLogged() check. The attack vector is network-based with no privileges required, attack complexity is low, and no user interaction is needed. An unauthenticated attacker can invoke the endpoint to decrypt arbitrary ciphertexts using provided private keys, offloading cryptographic work to the target server. This results in low confidentiality impact (exposure of key material in logs) and low availability impact (CPU exhaustion via repeated requests). No rate limiting exists to constrain attack volume. As of the advisory date, no patched version is available.
Affected products
- WWBN AVideo <= 25.0
Timeline
- 2026-03-19: disclosed: Published to GitHub Advisory Database
- 2026-03-18: advisory: Published by WWBN/AVideo repository