← voltar
CVE-2026-56342

AVideo - Server-Side Request Forgery in Live/test.php via statsURL Parameter

CVSS 6.1 MEDIUMEPSS 0.2%CWE-918
Vexday Risk Score
13Baixo
Decisão SSVC (CISA)
Track
Sem sinal de exploração → monitorar
CVSS 6.1EPSS 0.2%KEV nãoPoC Nuclei Metasploit Patch referenciado
Ciclo de vida
20 jun 2026Publicada no NVD
Recomendação: Monitorar — sem sinal de exploração no momento.
AVideo through version 27.0 contains a server-side request forgery vulnerability in plugin/Live/test.php that allows authenticated administrators to read arbitrary URLs via the statsURL parameter, which lacks isSSRFSafeURL() validation and accepts requests to private IP ranges and cloud metadata endpoints. Attackers can exploit this by crafting requests to internal services, cloud metadata endpoints like 169.254.169.254, and localhost to retrieve sensitive information including IAM credentials, internal service responses, and network configuration details.
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:N/SC:H/SI:N/SA:N
Produtos afetados
AVideo · AVideo

Quer saber se a sua infraestrutura está exposta a isto?

Falar com a TrueHacking →