AVideo 29.0 及以下版本存在一个盲型的服务器端请求伪造(blind SSRF)漏洞,位于 函数中。该函数执行 调用时,仅受到格式校验的保护,缺乏更严格的源地址限制。 拥有 权限的已认证用户可以存储攻击者选定的 URL 作为视频链接;随后,每当视频观看页面渲染时,都会触发该易受攻击函数的执行,从而利用内容类型预言机(content-type oracle)和基于时序的检测机制,对内部主机进行探测。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-91965 | 7.5 HIGH | WWBN AVideo through 29.0 Broken Access Control via Live Endpoints |
| CVE-2026-91966 | 5.8 MEDIUM | AVideo through 29.0 Unauthenticated SSRF via Host Header |
No comments yet