GHSA-6w2r-cfpc-23r5: AVideo has Unauthenticated IDOR - Playlist Information Disclosure
The /objects/playlistsFromUser.json.php endpoint returns all playlists for any user without requiring authentication or authorization. An unauthenticated attacker can enumerate user IDs and retrieve playlist information including playlist names, video IDs, and playlist status for any user on the platform.
References
Code Behaviors & Features
Detect and mitigate GHSA-6w2r-cfpc-23r5 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →