MEDIUM 6.9 NVD
CVE-2026-91966
AVideo through 29.0 contains an unauthenticated server-side request forgery vulnerability in the check_site_availability function that accepts attacker-controll
AVideo through 29.0 contains an unauthenticated server-side request forgery vulnerability in the check_site_availability function that accepts attacker-controlled HTTP Host headers. Attackers can send requests to submitIndex.php or ajax.php with arbitrary Host headers to probe internal network hosts and ports, following redirects without authentication.
References
- https://github.com/WWBN/AVideo/security/advisories/GHSA-rqg6-qcjv-55w5
- https://www.vulncheck.com/advisories/avideo-through-29.0-unauthenticated-ssrf-via-host-hea
This medium severity vulnerability with a CVSS score of 6.9 was published on 2026-09-15 via NVD.
vulnfeed aggregates 13549 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.