PT-2025-51872 · Avideo · Avideo

Valentin Lobstein

·

Published

2025-12-17

·

Updated

2025-12-21

·

CVE-2025-34439

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions AVideo versions prior to 20.1
Description AVideo versions prior to 20.1 are susceptible to an open redirect issue because of inadequate validation of the cancelUri parameter during user login. This allows an attacker to construct a link that redirects users to arbitrary external websites, potentially enabling phishing attacks.
Recommendations Update AVideo to version 20.1 or later.

Exploit

Fix

Open Redirect

Weakness Enumeration

Related Identifiers

CVE-2025-34439

Affected Products

Avideo