Executive brief
WWBN AVideo is a video hosting and sharing platform. An unauthenticated attacker can delete arbitrary .log files on the server, including critical audit logs that record security events, by exploiting a path traversal vulnerability in the API login code verification endpoint. This enables attackers to cover their tracks after other attacks and probe which files exist on the server.
Technical details
WWBN AVideo's API::get_api_login_code() endpoint constructs a filesystem path directly from an attacker-controlled 'code' parameter without validation, then unconditionally deletes the resulting file via unlink() before validating its contents. The vulnerability is reachable without authentication, accepts directory traversal sequences (e.g., "../../") to escape the intended login-code directory, and requires only that the target path ends in .log. By comparing error messages ("Code not found" vs. "Code is corrupted"), attackers can determine whether arbitrary .log files exist on the server. The endpoint enforces rate limiting (5 attempts per 300 seconds), which slows enumeration but does not prevent targeted deletion of specific files. As of August 2026, no patch has been released for the vulnerability.
Affected products
- WWBN AVideo 29.0 and earlier
Timeline
- 2026-08-18: disclosed
- 2026-09-01: advisory