Executive brief
WWBN AVideo is a self-hosted video platform that includes administrative dashboards for viewing platform statistics. The report4.json.php and report4.1.json.php endpoints fail to require authentication, allowing anyone to retrieve user registration counts and growth metrics without logging in. An attacker can enumerate how many users have registered on a target AVideo platform by sending simple web requests, potentially aiding reconnaissance for further attacks.
Technical details
This is an authentication bypass vulnerability affecting the report4.json.php and report4.1.json.php endpoints in WWBN AVideo through version 30.0. The vulnerable code directly echoes User::getUsersPerDayJSON() and User::getUsersCumulativePerDayJSON() without checking authorization, in contrast to related endpoints (report1/2/3.json.php) which enforce User::isAdmin() and User::canViewChart() checks. The vulnerability is remotely exploitable without authentication or user interaction—an attacker sends an unauthenticated GET request to either endpoint and receives HTTP 200 with {date: count} JSON data revealing daily and cumulative user registration statistics (CWE-200). No patch has been released as of the advisory date.
Affected products
- WWBN AVideo through 30.0
Timeline
- 2026-08-13: disclosed: GitHub security advisory GHSA-xv5m-gpmp-m72c published
- 2026-08-28: advisory: CVE-2026-81732 published on NVD