Impact
The vulnerability exists in the plugin Live/myLiveControls.save.json.php of WWBN AVideo up to version 30.0 and the master branch as of commit 4cb576e. The endpoint accepts GET parameters customUrl, customMessage, and autoRedirect without verifying a CSRF token or checking the request origin. Because only a logged‑in state is required, an attacker who lures a streamer to a malicious page can silently modify that streamer's externalOptions, setting the viewer‑redirect URL so that visitors are redirected to a phishing site or shown a spoofed message.
Affected Systems
Affected systems are installations of WWBN AVideo plugins, specifically AVideo releases through 30.0 and the master branch up to commit 4cb576e. The vulnerability is present in all builds that contain the Live/myLiveControls.save.json.php endpoint, regardless of whether the site has custom configuration. The product is identified by the common name WWBN AVideo and includes all versions of the affected plugin.
Risk and Exploitability
The CVSS score of 5.1 indicates a moderate risk and the EPSS score is not available, so the historical exploitation probability is unknown. The vulnerability is not listed in CISA KEV, which suggests no confirmed exploitation at the time of analysis. An attacker can exploit the flaw by tricking any logged‑in streamer into visiting a malicious site that issues a crafted GET request to the unprotected endpoint; no privileged access, network scan or other prerequisites are indicated in the description. Where an attacker controls a page served to the victim, the redirect change occurs silently, potentially compromising confidentiality and integrity of the view‑redirection functionality.
OpenCVE Enrichment