#VU125479 Missing Authorization in AVideo - CVE-2026-33761
Published: April 8, 2026
AVideo
World Wide Broadcast Network
Description
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to missing authorization in Scheduler plugin list.json.php endpoints when handling GET requests. A remote attacker can send simple GET requests to disclose sensitive information.
The exposed data includes scheduled tasks, internal callback URLs and parameters, admin-composed email subjects and HTML bodies, and mappings between users and email campaigns.