PT-2026-84995 · Avideo · Avideo
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
AVideo versions prior to commit c91b5975d
Description
An issue exists in the EPG parser that allows authenticated uploaders to perform Server-Side Request Forgery (SSRF), a technique where an attacker induces the server to make requests to an internal resource. An attacker can provide an internal URL through the
epg link parameter during the video upload process. The system only validates the syntax of the input and subsequently fetches the URL server-side during EPG generation without implementing SSRF protection checks.Recommendations
Update AVideo to a version beyond commit c91b5975d.
Avoid using the
epg link parameter during video uploads until the update is applied.Exploit
Fix
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Avideo