AVideo versions prior to 20.1 contain an open redirect vulnerability caused by insufficient validation of the siteRedirectUri parameter during user registration. Attackers can redirect users to external sites, facilitating phishing attacks.
References
Configurations
History
No history.
Information
Published : 2025-12-17 20:15
Updated : 2025-12-19 19:15
NVD link : CVE-2025-34440
Mitre link : CVE-2025-34440
CVE.ORG link : CVE-2025-34440
JSON object : View
Products Affected
wwbn
- avideo
CWE
CWE-601
URL Redirection to Untrusted Site ('Open Redirect')
