Описание
AVideo through 29.0 contains an unauthenticated server-side request forgery vulnerability in the check_site_availability function that accepts attacker-controlled HTTP Host headers. Attackers can send requests to submitIndex.php or ajax.php with arbitrary Host headers to probe internal network hosts and ports, following redirects without authentication.
EPSS
Процентиль: 32%
0.00383
Низкий
5.8 Medium
CVSS3
Дефекты
CWE-918
Связанные уязвимости
CVSS3: 5.8
github
3 дня назад
AVideo through 29.0 contains an unauthenticated server-side request forgery vulnerability in the check_site_availability function that accepts attacker-controlled HTTP Host headers. Attackers can send requests to submitIndex.php or ajax.php with arbitrary Host headers to probe internal network hosts and ports, following redirects without authentication.
EPSS
Процентиль: 32%
0.00383
Низкий
5.8 Medium
CVSS3
Дефекты
CWE-918