AVideo versions prior to 20.1 contain an open redirect vulnerability caused by insufficient validation of the siteRedirectUri parameter during user registration. Attackers can redirect users to external sites, facilitating phishing attacks.
References
Configurations
History
19 Dec 2025, 19:15
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
19 Dec 2025, 16:15
| Type | Values Removed | Values Added |
|---|---|---|
| Summary | (en) AVideo versions prior to 20.1 contain an open redirect vulnerability caused by insufficient validation of the siteRedirectUri parameter during user registration. Attackers can redirect users to external sites, facilitating phishing attacks. |
18 Dec 2025, 19:50
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Wwbn
Wwbn avideo |
|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 6.1 |
| CPE | cpe:2.3:a:wwbn:avideo:*:*:*:*:*:*:*:* | |
| References | () https://github.com/WWBN/AVideo/commit/4a53ab2056 - Patch | |
| References | () https://github.com/WWBN/AVideo/commit/77c70019b0 - Patch | |
| References | () https://www.vulncheck.com/advisories/avideo-open-redirect-via-siteredirecturi-parameter - Third Party Advisory |
17 Dec 2025, 20:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-12-17 20:15
Updated : 2025-12-19 19:15
NVD link : CVE-2025-34440
Mitre link : CVE-2025-34440
CVE.ORG link : CVE-2025-34440
JSON object : View
Products Affected
wwbn
- avideo
CWE
CWE-601
URL Redirection to Untrusted Site ('Open Redirect')
