#VU125447 Open redirect in AVideo - CVE-2026-33296
Published: April 8, 2026
AVideo
World Wide Broadcast Network
Description
The vulnerability allows a remote attacker to redirect users to an attacker-controlled site.
The vulnerability exists due to url redirection to an untrusted site in view/userLogin.php when processing a user-supplied redirectUri parameter during the login flow. A remote attacker can send a specially crafted login URL to redirect users to an attacker-controlled site.
User interaction is required to follow the crafted link and complete or dismiss the login popup before the redirect occurs.