#VU125508 Information disclosure in AVideo - CVE-2026-35452

 

#VU125508 Information disclosure in AVideo - CVE-2026-35452

Published: April 8, 2026


Vulnerability identifier: #VU125508
Vulnerability risk: Medium
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2026-35452
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vulnerable software:
AVideo
Software vendor:
World Wide Broadcast Network

Description

The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to improper access control in plugin/CloneSite/client.log.php when handling requests to the log endpoint. A remote attacker can send a request to the endpoint to disclose sensitive information.

If the CloneSite feature has been used, the exposed log may contain internal filesystem paths, remote server URLs, SSH connection metadata, and SQL dump file locations.


Remediation

Install security update from vendor's website.

External links