Report: - AVideo: Unauthenticated Access to Scheduler Plugin Endpoints Leaks Scheduled Tas... CVE-2026-33761

Report: - AVideo: Unauthenticated Access to Scheduler Plugin Endpoints Leaks Scheduled Tas... CVE-2026-33761

CVE ID :CVE-2026-33761 Published : March 27, 2026, 3:16 p.m. | 29 minutes ago Description :WWBN AVideo is an open source video platform. In versions up to and including 26.0, three `list.json.php` endpoints in the Scheduler plugin lack any authentication check, while every other endpoint in the same plugin directories (`add.json.php`, `delete.json.php`, `index.php`) requires `User::isAdmin()`. An unauthenticated attacker can retrieve all scheduled tasks (including internal callback URLs and parameters), admin-composed email messages, and user-to-email targeting mappings by sending simple GET requests. Commit 83390ab1fa8dca2de3f8fa76116a126428405431 contains a patch. Severity: 5.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVE Details

Severity
MEDIUM
Published
March 27, 2026
Affected Product: php