#VU125447 Open redirect in AVideo - CVE-2026-33296

 

#VU125447 Open redirect in AVideo - CVE-2026-33296

Published: April 8, 2026


Vulnerability identifier: #VU125447
Vulnerability risk: Medium
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2026-33296
CWE-ID: CWE-601
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vulnerable software:
AVideo
Software vendor:
World Wide Broadcast Network

Description

The vulnerability allows a remote attacker to redirect users to an attacker-controlled site.

The vulnerability exists due to url redirection to an untrusted site in view/userLogin.php when processing a user-supplied redirectUri parameter during the login flow. A remote attacker can send a specially crafted login URL to redirect users to an attacker-controlled site.

User interaction is required to follow the crafted link and complete or dismiss the login popup before the redirect occurs.


Remediation

Install security update from vendor's website.

External links