THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-91966 (MEDIUM 5.8) — AVideo through 29.0 contains an unauthenticated server-side request forgery vulnerability in the check_site_availability function that accepts attacker-controlled HTTP Host headers. Attackers can send requests to submitIndex.php or ajax.php with arbitrary Host headers to probe in

[NVD] CVE-2026-91966 (MEDIUM 5.8) — AVideo through 29.0 contains an unauthenticated server-side request forgery vulnerability in the check_site_availability function that accepts attacker-controlled HTTP Host headers. Attackers can send requests to submitIndex.php or ajax.php with arbitrary Host headers to probe in

mednvdPublished 2026-09-15

CVE-2026-91966 CVSS: 5.8 MEDIUM Published: 2026-09-15T16:17:52.783

AVideo through 29.0 contains an unauthenticated server-side request forgery vulnerability in the check_site_availability function that accepts attacker-controlled HTTP Host headers. Attackers can send requests to submitIndex.php or ajax.php with arbitrary Host headers to probe internal network hosts and ports, following redirects

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-91966