CVE Explorer
CVE-2026-46337
WWBN AVideo is an open source video platform. In 29.0 and earlier, an unauthenticated remote attacker can read arbitrary image files anywhere on disk that the PHP user can open — including private user-profile photos that the application's normal serving wrappers gate behind ACLs, admin-uploaded thumbnails, encrypted-video poster frames, and image content under sibling-app directories reachable via .. traversal. The endpoint requires no authentication.
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"product":"AVideo","vendor":"WWBN","versions":[{"status":"affected","version":"<= 29.0"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:f4733eccd6e449e710c95743fd213f36cda997197ae29806d51dac1045113ba4 · sha256:0589f0ba3bdb339c… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackRequirements":"NONE","attackVector":"NETWORK","baseScore":6.9,"baseSeverity":"MEDIUM","privilegesRequired":"NONE","subAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","userInteraction":"NONE","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N","version":"4.0","vulnAvailabilityImpact":"NONE","vulnConfidentialityImpact":"LOW","vulnIntegrityImpact":"NONE"},"metric_type":"cvssV4_0"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:f4733eccd6e449e710c95743fd213f36cda997197ae29806d51dac1045113ba4 · sha256:0589f0ba3bdb339c… · /containers/cna/metrics/0/cvssV4_0
CWE assertions
1 source assertion{"cweId":"CWE-22","description":"CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:f4733eccd6e449e710c95743fd213f36cda997197ae29806d51dac1045113ba4 · sha256:0589f0ba3bdb339c… · /containers/cna/problemTypes/0/descriptions/0
Source references
2 source assertions{"tags":["exploit"],"url":"https://github.com/WWBN/AVideo/security/advisories/GHSA-w4qq-74h6-58wq"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:f4733eccd6e449e710c95743fd213f36cda997197ae29806d51dac1045113ba4 · sha256:0589f0ba3bdb339c… · /containers/adp/0/references/0
{"name":"https://github.com/WWBN/AVideo/security/advisories/GHSA-w4qq-74h6-58wq","tags":["x_refsource_CONFIRM"],"url":"https://github.com/WWBN/AVideo/security/advisories/GHSA-w4qq-74h6-58wq"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:f4733eccd6e449e710c95743fd213f36cda997197ae29806d51dac1045113ba4 · sha256:0589f0ba3bdb339c… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.