6.1
CVE-2025-34440
- EPSS 0.16%
- Veröffentlicht 17.12.2025 19:48:57
- Zuletzt bearbeitet 19.12.2025 19:15:51
- Quelle disclosure@vulncheck.com
- CVE-Watchlists
- Unerledigt
AVideo < 20.1 Open Redirect via siteRedirectUri Parameter
AVideo versions prior to 20.1 contain an open redirect vulnerability caused by insufficient validation of the siteRedirectUri parameter during user registration. Attackers can redirect users to external sites, facilitating phishing attacks.
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.16% | 0.055 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 6.1 | 2.8 | 2.7 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
|
| disclosure@vulncheck.com | 4.8 | 0 | 0 |
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
|
CWE-601 URL Redirection to Untrusted Site ('Open Redirect')
The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect.
https://github.com/WWBN/AVideo/commit/4a53ab2056
https://github.com/WWBN/AVideo/commit/77c70019b0
https://www.vulncheck.com/advisories/avideo-open-redirect-via-siteredirecturi-parameter
https://chocapikk.com/posts/2025/avideo-security-vulnerabilities/