---
id: CVE-2020-37173
title: AVideo Platform 8.1 - Information Disclosure (User Enumeration)
summary: >-
  AVideo Platform 8.1 contains an information disclosure vulnerability that
  allows attackers to enumerate user details through the
  playlistsFromUser.json.php endpoint. Attackers can retrieve sensitive user
  information including email, pass…
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'
cvssSource: cna
cwe:
  - CWE-359
vendor: AVideo
product: AVideo Platform
affected:
  - platform 8.1
ssvc:
  exploitation: poc
  automatable: 'yes'
  technicalImpact: partial
  timestamp: '2026-02-12T19:09:44.641589Z'
exploitAvailable: true
published: '2026-02-11'
updated: '2026-10-01'
sourceUpdated: '2026-10-01T15:19:38.243Z'
source: CVEORG
sourceUrl: 'https://www.cve.org/CVERecord?id=CVE-2020-37173'
references:
  - url: 'https://www.exploit-db.com/exploits/47997'
    label: ExploitDB-47997
  - url: 'https://avideo.com'
    label: Official AVideo Platform Homepage
  - url: 'https://github.com/WWBN/AVideo'
    label: AVideo Platform GitHub Repository
  - url: >-
      https://www.vulncheck.com/advisories/avideo-platform-information-disclosure-user-enumeration
    label: >-
      VulnCheck Advisory: AVideo Platform 8.1 - Information Disclosure (User
      Enumeration)
tags:
  - cve.org
  - exploit-available
epss: 0.006
epssPercentile: 0.46758
ingestedAt: '2026-10-01T15:48:17.874Z'
---

## Overview

AVideo Platform 8.1 contains an information disclosure vulnerability that allows attackers to enumerate user details through the playlistsFromUser.json.php endpoint. Attackers can retrieve sensitive user information including email, password hash, and administrative status by manipulating the users_id parameter.

## Affected

- `platform 8.1`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
