PT-2026-92086 · Avideo · Avideo
CVSS v4.0
5.3
Medium
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
AVideo versions prior to 29.1
Description
A blind server-side request forgery exists in the
getHeaderContentTypeFromURL() function, which performs get headers() calls that are only protected by format validation. Authenticated users with canUpload permission can store malicious URLs as video links. This triggers the vulnerable function whenever a video watch page is rendered, allowing the probing of internal hosts through timing-based detection and content-type oracles (a method of inferring information based on the server's response headers).Recommendations
Update to a version newer than 29.0.
As a temporary mitigation, restrict the
canUpload permission to trusted users only.Exploit
Fix
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Avideo