PT-2026-83081 · Avideo · Avideo

·

CVE-2026-81733

·

Published

2026-08-28

·

Updated

2026-08-29

CVSS v4.0

5.1

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions AVideo versions prior to 30.1
Description A cross-site request forgery (CSRF) issue exists in the 'plugin/Live/myLiveControls.save.json.php' endpoint. The system verifies if a user is logged in but fails to enforce a CSRF token or origin check when processing the customUrl, customMessage, and autoRedirect parameters via a GET request. This allows an attacker to trick a logged-in streamer into visiting a malicious page, enabling the silent modification of live-channel viewer-redirect settings stored in users.externalOptions. Consequently, viewers may be redirected to phishing sites or presented with spoofed messages.
Recommendations Update AVideo to a version later than 30.0. As a temporary mitigation, restrict access to the 'plugin/Live/myLiveControls.save.json.php' endpoint or avoid using the customUrl, customMessage, and autoRedirect parameters until the update is applied.

Exploit

Fix

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-81733

Affected Products

Avideo