Impact
The flaw permits any unauthenticated remote user to issue HTTP requests to the submitIndex.php or ajax.php endpoints with attacker‑controlled Host headers. Because the application accepts the Host header unchanged and follows redirects without authentication, an attacker can force the server to make requests to arbitrary IP addresses and ports within the internal network, effectively performing an SSRF attack that can disclose internal host information or be leveraged for further lateral movement. This is a CWE‑918 weakness.
Affected Systems
The vulnerability is present in WWBN's AVideo application, affecting all installations of version 29.0 and earlier running the check_site_availability function. Any deployment that uses AVideo 29.0 or a predecessor is susceptible.
Risk and Exploitability
The CVSS score of 6.9 indicates moderate severity, and the EPSS score of <1% highlights a very low but non‑zero probability that the flaw will be exploited in the wild. It is not listed in the CISA KEV catalog. Attackers can exploit the flaw over the network without authentication by submitting crafted Host headers to the relevant endpoints, making it a convenient remote exploitation vector.
OpenCVE Enrichment