There was a local file disclosure vulnerability in AVideo < 8.9 via the proxy streaming. An unauthenticated attacker can exploit this issue to read an arbitrary file on the server. Which could leak database credentials or other sensitive information such as /etc/passwd file.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Avideo | Wwbn | * | 8.9 (excluding) |