Description
AVideo versions prior to 20.1 are vulnerable to an open redirect flaw due to missing validation of the cancelUri parameter during user login. An attacker can craft a link to redirect users to arbitrary external sites, enabling phishing attacks.
Problem types
CWE-601 URL Redirection to Untrusted Site ('Open Redirect')
Product status
Any version before 20.1
Credits
Valentin Lobstein (Chocapikk)
References
github.com/WWBN/AVideo/commit/4a53ab2056
github.com/WWBN/AVideo/commit/88bc40427b
www.vulncheck.com/...o-open-redirect-via-canceluri-parameter
chocapikk.com/posts/2025/avideo-security-vulnerabilities/
Data based on CVE®. Copyright © 1999-2025, The MITRE Corporation. All rights reserved.