Executive brief
AVideo is a video platform that allows users to manage playlists. The platform fails to validate redirect URLs when processing playlist reordering requests, allowing an attacker to craft a malicious link that redirects authenticated users to a phishing site after the victim's playlist is reordered. This could lead to credential theft and account compromise.
Technical details
The vulnerability is an open redirect (CWE-601) combined with cross-site request forgery (CWE-352) in objects/playlistSort.php. The endpoint lacks the automatic CSRF protection that normally applies to AVideo's *.json.php scripts because it uses a different naming convention. When processing a sort request, the script sets a Location header to the unvalidated $_SERVER['HTTP_REFERER'] value without calling isSafeRedirectURL(). An attacker can craft a cross-origin POST request with a malicious Referer header targeting a logged-in user who manages the playlist, causing the victim's browser to redirect to an attacker-controlled site. The attack requires the victim to have existing permissions (canManagePlaylist) and to click a malicious link, but no patch is currently available.
Affected products
- WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1
Timeline
- 2026-08-27: disclosed
- 2026-09-11: advisory