#VU125490 Missing Authorization in AVideo - CVE-2026-34395
Published: April 8, 2026
AVideo
World Wide Broadcast Network
Description
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to missing authorization in plugin/YPTWallet/view/users.json.php when handling requests to the users.json.php endpoint. A remote user can send a request to retrieve all platform users' personal information and wallet balances to disclose sensitive information.
The endpoint is accessible to any authenticated user and exposes data for all users, including admin accounts.