Missing Authentication for Critical Function in AVideo - #VU125449

 

Missing Authentication for Critical Function in AVideo - #VU125449

Published: April 8, 2026


Vulnerability identifier: #VU125449
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-306
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to disclose sensitive information and cause a denial of service.

The vulnerability exists due to missing authentication for a critical function in decryptMessage.json.php when handling decryption requests. A remote attacker can send specially crafted decryption requests to disclose sensitive information and cause a denial of service.

Submitted private key material may be exposed through server memory or logging infrastructure depending on server configuration.


Affected software

AVideo

Remediation

Install security update from vendor's website.


External References