Executive brief
WWBN AVideo is a video streaming and management platform. The TopMenu plugin endpoint fails to require authentication, allowing anyone on the network to retrieve sensitive menu configuration data including inactive and admin-only menus that should only be visible to authorized administrators. This information disclosure could help attackers map the system's internal structure and identify hidden administrative features.
Technical details
The vulnerability is a missing authentication issue (CWE-306) in the plugin/TopMenu/menus.json.php endpoint. The endpoint calls Menu::getAll() without requiring User::isAdmin() authentication, whereas the related menuSave.json.php correctly enforces admin authentication. An unauthenticated attacker can send a GET request to this endpoint over the network to retrieve all menu records as JSON, including inactive menus and admin-only entries. No user interaction or special privileges are required for exploitation. At the time of reporting, no patch was available; the vulnerability exists through at least commit c3edcc274c389816d434acadac07ee78eaf330c1.
Affected products
- WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1
Timeline
- 2026-08-28: disclosed
- 2026-09-12: advisory