Impact
A Server‑Side Request Forgery vulnerability exists in AVideo, triggered by the epg_link parameter during video upload. Authenticated uploaders can supply any internal URL; the parameter is only syntactically validated and later fetched without SSRF protection. A successful exploit allows the attacker to read arbitrary internal resources, potentially exposing sensitive configuration data, internal services, or compromising system integrity, as the attacker can reach any internal endpoint the server can access. The weakness is identified as CWE‑918.
Affected Systems
The affected product is AVideo from WWBN. The vulnerability exists in versions up to the commit c91b5975d. No precise version numbers are listed, so all releases before the vendor’s fix are considered at risk.
Risk and Exploitability
The CVSS score of 7.1 indicates a high‑severity threat. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalogue, suggesting no widespread exploitation yet. However, because only authenticated uploaders can trigger the flaw, the attack requires legitimate credentials. Given the lack of SSRF defenses, a determined attacker with upload access can enumerate internal endpoints and retrieve data, making the risk significant for organizations that expose AVideo to untrusted users.
OpenCVE Enrichment