Executive brief
WWBN AVideo is a self-hosted video streaming platform. The Bookmark plugin endpoint fails to validate user permissions, allowing unauthenticated attackers to retrieve chapter metadata (chapter names and timestamps) from password-protected videos. This leaks sensitive content structure information that should only be accessible to authorized viewers.
Technical details
The Bookmark plugin endpoint `getBookmarks.json.php` instantiates a Video object and retrieves bookmarks via `BookmarkTable::getAllFromVideo()` without calling `User::canWatchVideo()` to verify the requester's permission to access the video. The vulnerability is a missing authorization check (CWE-862, CWE-200) in an unauthenticated, network-accessible endpoint. An attacker can craft a GET request with a `videos_id` parameter pointing to any password-protected video and receive the full chapter metadata in JSON format. No authentication, password validation, or user interaction is required. Fix status: unfixed at time of advisory publication (Aug 28, 2026).
Affected products
- WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1
Timeline
- 2026-08-28: disclosed
- 2026-09-12: advisory