Description
AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains an open redirect in objects/playlistSort.php. Because the endpoint is not a *.json.php script, AVideo's automatic CSRF guard (autoCSRFGuard()/forbidIfIsUntrustedRequest()) does not run, and when the request includes the sort parameter the script issues a Location header set to the unvalidated $_SERVER['HTTP_REFERER'] value without calling isSafeRedirectURL(). A remote unauthenticated attacker can therefore induce a logged-in user who can manage the targeted playlist to submit a cross-origin POST with a crafted Referer, causing the victim's playlist to be reordered and the victim's browser to be redirected from a trusted AVideo URL to an attacker-controlled site for phishing. No patched version is available.
Published: 2026-09-11
Score: 5.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthenticated remote denial to user phishing via open redirect
Action: Mitigate
AI Analysis

Impact

AVideo’s playlistSort.php contains an empty redirect that uses the unfiltered HTTP_REFERER header to build a Location response. When a user performs a playlist reorder with a crafted request, the application issues a redirect to an arbitrary URL supplied by the attacker. This behavior can be used to lure a logged‑in playlist manager into visiting a malicious site, enabling phishing or credential‑stealing attacks. The weakness is a type of cross‑site request forgery (CWE‑352) because the script accepts a request that can be triggered without the user’s explicit intent and then performs an unauthorized redirect.

Affected Systems

All instances of WWBN:AVideo that include the commit c3edcc274c389816d434acadac07ee78eaf330c1 or earlier. No patch version is currently released, so any installation based on this code is potentially vulnerable unless the handle is manually removed or modified.

Risk and Exploitability

The CVSS score of 5.1 suggests medium severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. The attack can be executed by an unauthenticated remote actor that sends a crafted POST request to the endpoint and specifies a malicious Referer header. Because the script skips its CSRF guard, the attack can be triggered without the victim’s credentials and can redirect any authenticated user who manages the targeted playlist.

Generated by OpenCVE AI on September 11, 2026 at 14:10 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the code fix that validates the Referer header or removes the redirect logic from playlistSort.php before deploying to production
  • Restrict access to playlistSort.php such that only trusted internal requests reach it, for example by requiring a specific authenticated session token in addition to the existing authentication checks
  • Deploy a Web Application Firewall rule to detect and block requests to playlistSort.php that contain suspicious Referer headers, or to enforce that redirect destinations are confined to the same host

Generated by OpenCVE AI on September 11, 2026 at 14:10 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 11 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 11 Sep 2026 11:30:00 +0000

Type Values Removed Values Added
Description AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains an open redirect in objects/playlistSort.php. Because the endpoint is not a *.json.php script, AVideo's automatic CSRF guard (autoCSRFGuard()/forbidIfIsUntrustedRequest()) does not run, and when the request includes the sort parameter the script issues a Location header set to the unvalidated $_SERVER['HTTP_REFERER'] value without calling isSafeRedirectURL(). A remote unauthenticated attacker can therefore induce a logged-in user who can manage the targeted playlist to submit a cross-origin POST with a crafted Referer, causing the victim's playlist to be reordered and the victim's browser to be redirected from a trusted AVideo URL to an attacker-controlled site for phishing. No patched version is available.
Title AVideo Open Redirect via playlistSort.php Referer Header
First Time appeared Wwbn
Wwbn avideo
Weaknesses CWE-352
CPEs cpe:2.3:a:wwbn:avideo:-:*:*:*:*:*:*:*
Vendors & Products Wwbn
Wwbn avideo
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'}

cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-11T12:50:13.116Z

Reserved: 2026-09-11T01:23:39.045Z

Link: CVE-2026-89148

cve-icon Vulnrichment

Updated: 2026-09-11T12:49:33.437Z

cve-icon NVD

Status : Deferred

Published: 2026-09-11T12:16:53.170

Modified: 2026-09-11T15:21:12.850

Link: CVE-2026-89148

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T16:45:14Z

Weaknesses
  • CWE-352

    Cross-Site Request Forgery (CSRF)