WWBN AVideo versions 29.0 and prior contain an information disclosure vulnerability in the git.json.php file, which executes git log commands and returns sensitive output to unauthenticated users. This open-source video platform flaw exposes deployed commit hashes, developer personally identifiable information including names and email addresses, and commit messages that may reference internal systems or security measures. The vulnerability has a CVSS 3.1 score of 5.3 (Medium) with a network-based attack vector requiring no authentication or user interaction, making it trivial to exploit remotely. The impact is limited to confidentiality loss, as attackers cannot modify data or disrupt service availability, but the exposed information enables version fingerprinting against known CVEs and potentially provides reconnaissance data for follow-on attacks. No evidence of active exploitation has been reported, and the vulnerability is not tracked on CISA's Known Exploited Vulnerabilities list. However, as of publication there are no known patched versions available, leaving all affected deployments vulnerable. The low EPSS score of 0.00031 and inactive Hot List status suggest minimal current community attention, but organizations running WWBN AVideo should implement access controls to restrict git.json.php or upgrade immediately upon patch availability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 29.0CPE matchmatch criteria | cpe:2.3:a:wwbn:avideo:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.