Impact
AVideo’s playlistSort.php contains an empty redirect that uses the unfiltered HTTP_REFERER header to build a Location response. When a user performs a playlist reorder with a crafted request, the application issues a redirect to an arbitrary URL supplied by the attacker. This behavior can be used to lure a logged‑in playlist manager into visiting a malicious site, enabling phishing or credential‑stealing attacks. The weakness is a type of cross‑site request forgery (CWE‑352) because the script accepts a request that can be triggered without the user’s explicit intent and then performs an unauthorized redirect.
Affected Systems
All instances of WWBN:AVideo that include the commit c3edcc274c389816d434acadac07ee78eaf330c1 or earlier. No patch version is currently released, so any installation based on this code is potentially vulnerable unless the handle is manually removed or modified.
Risk and Exploitability
The CVSS score of 5.1 suggests medium severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. The attack can be executed by an unauthenticated remote actor that sends a crafted POST request to the endpoint and specifies a malicious Referer header. Because the script skips its CSRF guard, the attack can be triggered without the victim’s credentials and can redirect any authenticated user who manages the targeted playlist.
OpenCVE Enrichment