CVE-2026-35452

MEDIUM

WWBN AVideo has Unauthenticated Information Disclosure via Missing Auth on CloneSite client.log.php

Title source: cna

Description

WWBN AVideo is an open source video platform. In versions 26.0 and prior, the plugin/CloneSite/client.log.php endpoint serves the clone operation log file without any authentication. Every other endpoint in the CloneSite plugin directory enforces User::isAdmin(). The log contains internal filesystem paths, remote server URLs, and SSH connection metadata.

Scores

CVSS v3 5.3
EPSS 0.0001
EPSS Percentile 2.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Details

CWE
CWE-200
Status published
Products (3)
wwbn/avideo < 26.0
wwbn/avideo 0Packagist
WWBN/AVideo <= 26.0
Published Apr 06, 2026
Tracked Since Apr 07, 2026