WWBN AVideo
cpe:2.3:a:wwbn:avideo:*:*:*:*:*:*:*
- < 20.0
A open redirect vulnerability has been identified in AVideo versions prior to 20.0. This vulnerability arises from inadequate validation of the siteRedirectUri parameter during user registration, allowing attackers to redirect users to external sites and potentially facilitate phishing attacks.
Exploitation of this vulnerability allows for open redirection, where users can be sent to untrusted sites, increasing the risk of phishing attacks.
To reproduce this vulnerability, register a new user account and include a malicious URL in the siteRedirectUri parameter. The application will redirect the user to the specified URL, bypassing security measures.
Users can upgrade to AVideo version 20.0 or later, where this vulnerability has been addressed.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.