PT-2026-83081 · Avideo · Avideo
CVSS v4.0
5.1
Medium
| Vector | AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
AVideo versions prior to 30.1
Description
A cross-site request forgery (CSRF) issue exists in the 'plugin/Live/myLiveControls.save.json.php' endpoint. The system verifies if a user is logged in but fails to enforce a CSRF token or origin check when processing the
customUrl, customMessage, and autoRedirect parameters via a GET request. This allows an attacker to trick a logged-in streamer into visiting a malicious page, enabling the silent modification of live-channel viewer-redirect settings stored in users.externalOptions. Consequently, viewers may be redirected to phishing sites or presented with spoofed messages.Recommendations
Update AVideo to a version later than 30.0.
As a temporary mitigation, restrict access to the 'plugin/Live/myLiveControls.save.json.php' endpoint or avoid using the
customUrl, customMessage, and autoRedirect parameters until the update is applied.Exploit
Fix
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Avideo