AVideo through 29.0 contains an unauthenticated server-side request forgery vulnerability in the check_site_availability function that accepts attacker-controlled HTTP Host headers. Attackers can send requests to submitIndex.php or ajax.php with arbitrary Host headers to probe internal network hosts and ports, following redirects without authentication.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-09-15 16:17
Updated : 2026-09-15 16:17
NVD link : CVE-2026-91966
Mitre link : CVE-2026-91966
CVE.ORG link : CVE-2026-91966
JSON object : View
Products Affected
No product.
CWE
CWE-918
Server-Side Request Forgery (SSRF)
