← back
CVE-2025-34441mediumCWE-359

AVideo < 20.1 User Information Disclosure via Public API

28Vexday Risk Score

Patch soon. It has a working public exploit.

ssvc Attendcvss 6.9epss 0.8%
from disclosure to weapon2 days
Published on NVDDec 17
metasploit+2d
exploitation probability
0.8%top 48% of all CVEs
observed exploitation
nono source reports it
AVideo versions prior to 20.1 expose sensitive user information through an unauthenticated public API endpoint. Responses include emails, usernames, administrative status, and last login times, enabling user enumeration and privacy violations.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N