CVE-2020-23490: Wwbn Avideo

High severity, CVSS 7.5. EPSS: 2.6% chance of exploitation in the next 30 days.

There was a local file disclosure vulnerability in AVideo < 8.9 via the proxy streaming. An unauthenticated attacker can exploit this issue to read an arbitrary file on the server. Which could leak database credentials or other sensitive information such as /etc/passwd file.

Affected products

  • Wwbn Avideo: before 8.9 (fixed in 8.9)

Published 2020-11-16. Last modified 2026-06-17.