CyberRota Analysis
AI-GeneratedAVideo versions up to 29.0 are vulnerable to an information disclosure flaw in the stats.json.php endpoint, allowing unauthenticated attackers to access sensitive stream keys and m3u8 URLs. This vulnerability enables the enumeration of private and restricted live streams, potentially exposing sensitive streaming credentials. Organizations using AVideo should prioritize patching this vulnerability to protect their streaming content and user privacy.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
AVideo through 29.0 contains an information disclosure vulnerability in plugin/Live/stats.json.php that allows unauthenticated attackers to retrieve stream keys and m3u8 URLs by accessing the endpoint without authentication. Attackers can enumerate private, unlisted, and group-restricted live streams by parsing the hidden_applications array in the JSON response to obtain sensitive streaming credentials.