Junglewise Threat Intelligence

CVE-2026-89148: AVideo open redirect in playlistSort.php

CVE-2026-89148 · Severity: medium · CVSS 5.4 · Published 2026-09-11

Technologies: WWBN AVideo. Vendors: WWBN.

Executive brief

AVideo is a video platform that allows users to manage playlists. The platform fails to validate redirect URLs when processing playlist reordering requests, allowing an attacker to craft a malicious link that redirects authenticated users to a phishing site after the victim's playlist is reordered. This could lead to credential theft and account compromise.

Technical details

The vulnerability is an open redirect (CWE-601) combined with cross-site request forgery (CWE-352) in objects/playlistSort.php. The endpoint lacks the automatic CSRF protection that normally applies to AVideo's *.json.php scripts because it uses a different naming convention. When processing a sort request, the script sets a Location header to the unvalidated $_SERVER['HTTP_REFERER'] value without calling isSafeRedirectURL(). An attacker can craft a cross-origin POST request with a malicious Referer header targeting a logged-in user who manages the playlist, causing the victim's browser to redirect to an attacker-controlled site. The attack requires the victim to have existing permissions (canManagePlaylist) and to click a malicious link, but no patch is currently available.

Affected products

  • WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1

Timeline

  • 2026-08-27: disclosed
  • 2026-09-11: advisory

References

Related threats