PT-2026-92085 · Avideo · Avideo

·

CVE-2026-91966

·

Published

2026-09-15

·

Updated

2026-09-20

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions AVideo versions prior to 29.0
Description An unauthenticated server-side request forgery (SSRF) issue exists in the check site availability() function. This occurs because the function accepts attacker-controlled HTTP Host headers. By sending requests to the 'submitIndex.php' or 'ajax.php' endpoints with arbitrary Host headers, an attacker can probe internal network hosts and ports by following redirects without authentication. Server-side request forgery is a flaw that allows an attacker to induce the server-side application to make requests to an unintended location.
Recommendations Update to a version newer than 29.0. As a temporary mitigation, restrict access to the 'submitIndex.php' and 'ajax.php' endpoints or disable the check site availability() function.

Exploit

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-91966
GHSA-RQG6-QCJV-55W5

Affected Products

Avideo