Open Redirect Vulnerability in AVideo Software by WWBN
CVE-2026-89148
5.1MEDIUM
What is CVE-2026-89148?
AVideo contains a significant vulnerability in the playlist sorting functionality due to an open redirect flaw. The issue arises from the handling of the 'sort' parameter in the objects/playlistSort.php script, where the endpoint does not trigger the automatic CSRF guard. As a result, a remote attacker can manipulate the HTTP_REFERER value, leading to unauthorized reordering of user playlists. This flaw enables phishing attacks by redirecting users from a trusted AVideo URL to a malicious site, posing a serious security risk especially for logged-in users with playlist management permissions. No patch is currently available to address this vulnerability.
Affected Version(s)
AVideo 0
