#VU125508 Information disclosure in AVideo - CVE-2026-35452
Published: April 8, 2026
AVideo
World Wide Broadcast Network
Description
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to improper access control in plugin/CloneSite/client.log.php when handling requests to the log endpoint. A remote attacker can send a request to the endpoint to disclose sensitive information.
If the CloneSite feature has been used, the exposed log may contain internal filesystem paths, remote server URLs, SSH connection metadata, and SQL dump file locations.