There was a local file disclosure vulnerability in AVideo < 8.9 via the proxy streaming. An unauthenticated attacker can exploit this issue to read an arbitrary file on the server. Which could leak database credentials or other sensitive information such as /etc/passwd file.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Avideo | Wwbn | * | 8.9 (excluding) |