Executive brief
MediaCMS is an open-source video management platform. A security flaw allows logged-in users to view private information about videos they do not own, such as titles, descriptions, and view counts. While the actual video files remain protected, this leak could expose sensitive internal information or private user activity.
Technical details
An incorrect authorization vulnerability (CWE-863) exists in MediaCMS 8.2.0. Authenticated users can perform a PUT request to the playlist API endpoint to add any media token to their own playlist, bypassing state and ownership validation. Because the playlist detail view returns all media metadata to the playlist owner without filtering, the attacker can then retrieve private fields including title, description, view count, like count, file size, and author username. The actual media stream is not affected as it is protected by a separate Nginx auth-request layer. A fix has been acknowledged by the maintainers in the project's issue tracker.
Affected products
- MediaCMS MediaCMS 8.2.0
Timeline
- 2026-06-05: disclosed: Initial report submitted via GHSA
- 2026-07-08: patched: Fix confirmed by reporter in GitHub issue
- 2026-07-21: advisory: NVD and VulnCheck publication date