AVideo vulnerability

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a missing authentication vulnerability in the plugin/TopMenu/menuItems.json.php endpoint that allows unauthenticated attackers to read inactive admin menu items by submitting a POST request with a menuId parameter. Attackers can retrieve hidden menu item URLs including embedded admin-tool secret query parameters not exposed in the public navbar.

Published 12 Sep 2026Updated 12 Sep 20262 sources
CVSS 6.9

Record history

Record created from the first normalized source observation.
Metadata and source references refreshed.