WWBN AVideo Server-Side Request Forgery Vulnerability in LiveLinks Plugin

Vulnerability

A server-side request forgery (SSRF) vulnerability has been identified in the WWBN AVideo platform, specifically in versions through 25.0. The issue resides in the plugin/LiveLinks/proxy.php endpoint, which improperly validates user-supplied URLs against internal networks. While the initial URL is checked for safety, any HTTP redirects are followed without re-validation, allowing attackers to access internal services and metadata through controlled redirects. This vulnerability is present in an unauthenticated endpoint that directly interacts with the user-supplied URLs.

Impact

Exploitation of this vulnerability allows attackers to access internal services and cloud metadata, including sensitive information such as IAM credentials on AWS, through an attacker-controlled redirect. The vulnerability could also be used to probe internal networks and services, potentially leading to further exploitation.

Reproduction

To reproduce this vulnerability, send a request to the AVideo instance's LiveLinks proxy endpoint with a URL that redirects to an internal service, such as cloud metadata. The request will bypass SSRF protections and return the internal data, including cloud IAM credentials if the redirect targets a metadata service.

Remediation

Users are advised to update to AVideo version 26.0 or later, where this vulnerability has been fixed.

Added: Mar 20, 2026, 6:20 AM
Updated: Mar 20, 2026, 6:20 AM

Vulnerability Rating

Custom Algorithm
spread
1.0
impact
0.6
exploitability
9.1
remediation
7.7
relevance
4.2
threat
6.4
urgency
2.9
incentive
8.3

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.