CVE-2020-37173: AVideo Platform 8.1 - Information Disclosure (User Enumeration)
AVideo Platform 8.1 contains an information disclosure vulnerability that allows attackers to enumerate user details through the playlistsFromUser.json.php endpoint. Attackers can retrieve sensitive user information including email, password hash, and administrative status by manipulating the usersid parameter.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-37173?
CVE-2020-37173 is categorized as a medium severity vulnerability due to its potential for information disclosure.
How do I fix CVE-2020-37173?
To mitigate CVE-2020-37173, users should upgrade to a version of AVideo Platform that addresses this vulnerability.
What type of information is disclosed in CVE-2020-37173?
CVE-2020-37173 allows attackers to enumerate sensitive user details, including email addresses and possibly passwords.
Which versions of AVideo Platform are affected by CVE-2020-37173?
AVideo Platform version 8.1 is the specific version affected by CVE-2020-37173.
How does CVE-2020-37173 expose user information?
CVE-2020-37173 utilizes the playlistsFromUser.json.php endpoint to leak user details through enumeration.