Impact
AVideo versions up to 29.0 have a blind SSRF flaw in the getHeaderContentTypeFromURL helper. The function issues get_headers() for supplied URLs without proper authorization checks, relying only on format validation. An attacker with the canUpload privilege can embed arbitrary URLs as video links. When a attacker‑chosen target is requested, the vulnerable function execution probes internal hosts using content‑type oracles and timing‑based detection. The flaw is a CWE‑918 weakness and allows covert visits to internal destinations by an authenticated user, exposing internal network resources without elevated privileges.
Affected Systems
The affected product is WWBN:AVideo, all releases through version 29.0. The vulnerability appears in the getHeaderContentTypeFromURL routine older releases are not impacted.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity. The EPSS score of < 1% suggests that the likelihood of this vulnerability being exploited in the wild is very low. This vulnerability is not listed in the CISA KEV catalog. Attackers would need to obtain authenticated upload rights; once held, they can exercise SSRF against any internal host reachable from the web server. The lack of outbound restrictions permits probing by content‑type oracles and timing, providing valuable network reconnaissance. Given these conditions, the risk is moderate but significant for systems exposed to an internal network or hosting sensitive endpoints.
OpenCVE Enrichment