Description
AVideo through 29.0 contains an unauthenticated server-side request forgery vulnerability in the check_site_availability function that accepts attacker-controlled HTTP Host headers. Attackers can send requests to submitIndex.php or ajax.php with arbitrary Host headers to probe internal network hosts and ports, following redirects without authentication.
Published: 2026-09-15
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Server‑Side Request Forgery (SSRF)
Action: Patch Now
AI Analysis

Impact

The flaw permits any unauthenticated remote user to issue HTTP requests to the submitIndex.php or ajax.php endpoints with attacker‑controlled Host headers. Because the application accepts the Host header unchanged and follows redirects without authentication, an attacker can force the server to make requests to arbitrary IP addresses and ports within the internal network, effectively performing an SSRF attack that can disclose internal host information or be leveraged for further lateral movement. This is a CWE‑918 weakness.

Affected Systems

The vulnerability is present in WWBN's AVideo application, affecting all installations of version 29.0 and earlier running the check_site_availability function. Any deployment that uses AVideo 29.0 or a predecessor is susceptible.

Risk and Exploitability

The CVSS score of 6.9 indicates moderate severity, and the EPSS score of <1% highlights a very low but non‑zero probability that the flaw will be exploited in the wild. It is not listed in the CISA KEV catalog. Attackers can exploit the flaw over the network without authentication by submitting crafted Host headers to the relevant endpoints, making it a convenient remote exploitation vector.

Generated by OpenCVE AI on September 20, 2026 at 16:21 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update AVideo to a patched version later than 29.0 that resolves the SSRF flaw.
  • If an upgrade cannot be performed immediately, configure the web server, reverse proxy, or application to reject requests that contain arbitrary non‑HTTPS Host headers, effectively blocking the SSRF exploitation path.
  • Deploy a properly configured web application firewall or intrusion detection system to detect and block suspicious redirect behavior or unusually broad Host header values, and monitor logs for internal network probing activity.

Generated by OpenCVE AI on September 20, 2026 at 16:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 01:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Description AVideo through 29.0 contains an unauthenticated server-side request forgery vulnerability in the check_site_availability function that accepts attacker-controlled HTTP Host headers. Attackers can send requests to submitIndex.php or ajax.php with arbitrary Host headers to probe internal network hosts and ports, following redirects without authentication.
Title AVideo through 29.0 Unauthenticated SSRF via Host Header
First Time appeared Wwbn
Wwbn avideo
Weaknesses CWE-918
CPEs cpe:2.3:a:wwbn:avideo:*:*:*:*:*:*:*:*
Vendors & Products Wwbn
Wwbn avideo
References
Metrics cvssV3_1

{'score': 5.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-20T00:35:29.357Z

Reserved: 2026-09-15T11:08:44.670Z

Link: CVE-2026-91966

cve-icon Vulnrichment

Updated: 2026-09-20T00:30:23.906Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T16:17:52.783

Modified: 2026-09-20T01:16:34.360

Link: CVE-2026-91966

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T16:30:18Z

Weaknesses
  • CWE-918

    Server-Side Request Forgery (SSRF)