CVE-2025-34441 - AVideo < 20.0 User Information Disclosure via Public API

CVE-2025-34441 - AVideo < 20.0 User Information Disclosure via Public API

CVE ID : CVE-2025-34441 Published : Dec. 17, 2025, 8:15 p.m. | 37 minutes ago Description : AVideo versions prior to 20.0 expose sensitive user information through an unauthenticated public API endpoint. Responses include emails, usernames, administrative status, and last login times, enabling user enumeration and privacy violations. Severity: 6.9 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVE Details

Severity
MEDIUM
Published
Dec. 17, 2025

Source: Telegram CVE Monitor