Daniel Neto

127 exploits Active since May 2023
CVE-2025-34441 WRITEUP HIGH WRITEUP
AVideo < 20.1 - Unauthenticated Exposure of Sensitive User Information via Public API
AVideo versions prior to 20.1 expose sensitive user information through an unauthenticated public API endpoint. Responses include emails, usernames, administrative status, and last login times, enabling user enumeration and privacy violations.
CVSS 7.5
CVE-2025-34442 WRITEUP HIGH WRITEUP
AVideo < 20.1 - Sensitive System Information Exposure via Public API Endpoints
AVideo versions prior to 20.1 disclose absolute filesystem paths via multiple public API endpoints. Returned metadata includes full server paths to media files, revealing underlying filesystem structure and facilitating more effective attack chains.
CVSS 7.5