CVE-2020-23490: Wwbn Avideo
High severity, CVSS 7.5. EPSS: 2.6% chance of exploitation in the next 30 days.
There was a local file disclosure vulnerability in AVideo < 8.9 via the proxy streaming. An unauthenticated attacker can exploit this issue to read an arbitrary file on the server. Which could leak database credentials or other sensitive information such as /etc/passwd file.
Affected products
- Wwbn Avideo: before 8.9 (fixed in 8.9)
Published 2020-11-16. Last modified 2026-06-17.