CyberRota Analysis
AI-GeneratedThe vulnerability exists in the plugin/TopMenu/menuItems.json.php endpoint of WWBN AVideo, where a lack of authentication allows unauthenticated attackers to access inactive admin menu items. This could lead to the exposure of sensitive URLs and admin-tool secret query parameters, potentially facilitating further attacks. Organizations using this software should prioritize patching this vulnerability to protect their administrative interfaces from unauthorized access.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a missing authentication vulnerability in the plugin/TopMenu/menuItems.json.php endpoint that allows unauthenticated attackers to read inactive admin menu items by submitting a POST request with a menuId parameter. Attackers can retrieve hidden menu item URLs including embedded admin-tool secret query parameters not exposed in the public navbar.