CVE-2026-33296
WWBN AVideo is an open source video platform. Prior to version 26.0, WWBN/AVideo contains an open redirect vulnerability
WWBN AVideo is an open source video platform. Prior to version 26.0, WWBN/AVideo contains an open redirect vulnerability in the login flow where a user-supplied redirectUri parameter is reflected directly into a JavaScript document.location assignment without JavaScript-safe encoding. After a user completes the login popup flow, a timer callback executes the redirect using the unvalidated value, sending the victim to an attacker-controlled site.
Version 26.0 fixes the issue.
MEDIUM · CVSS 6.1
EPSS 0.00049
Schedule remediation
- Public exploit or PoC is available
Sigma rules0
YARA rules0