Back to overview

CVE-2026-56342

MEDIUM
6.8
CVSS 3.1
Description
AVideo through version 27.0 contains a server-side request forgery vulnerability in plugin/Live/test.php that allows authenticated administrators to read arbitrary URLs via the statsURL parameter, which lacks isSSRFSafeURL() validation and accepts requests to private IP ranges and cloud metadata endpoints. Attackers can exploit this by crafting requests to internal services, cloud metadata endpoints like 169.254.169.254, and localhost to retrieve sensitive information including IAM credentials, internal service responses, and network configuration details.

Metadata

CVE ID
CVE-2026-56342
State
PUBLISHED
Assigner
VulnCheck
Reserved
2026-06-20 13:13 UTC
Published
2026-06-20 18:27 UTC
Last updated
2026-06-20 18:27 UTC
Primary CWE
CWE-918
Server-Side Request Forgery (SSRF)
Vendor / Product
AVideo / AVideo
Sources
cve.org  ·  NVD

Severity & Metrics

6.8 MEDIUM CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N
Affected products (1)
VendorProductPlatformVersions
AVideo AVideo 0 ≤ 27.0
Weakness (CWE)
CWESourceDescription
CWE-918 cna Server-Side Request Forgery (SSRF)
CVSS scores (2)
ScoreSeverityVersionSourceVector
6.8 MEDIUM 3.1 cna CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N
6.1 MEDIUM 4.0 cna CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:N/SC:H/SI:N/SA:N
References (2)
Back to overview