THREAT OPS › Threat News › [NVD] CVE-2026-91966 (MEDIUM 5.8) — AVideo through 29.0 contains an unauthenticated server-side request forgery vulnerability in the check_site_availability function that accepts attacker-controlled HTTP Host headers. Attackers can send requests to submitIndex.php or ajax.php with arbitrary Host headers to probe in
[NVD] CVE-2026-91966 (MEDIUM 5.8) — AVideo through 29.0 contains an unauthenticated server-side request forgery vulnerability in the check_site_availability function that accepts attacker-controlled HTTP Host headers. Attackers can send requests to submitIndex.php or ajax.php with arbitrary Host headers to probe in
CVE-2026-91966 CVSS: 5.8 MEDIUM Published: 2026-09-15T16:17:52.783
AVideo through 29.0 contains an unauthenticated server-side request forgery vulnerability in the check_site_availability function that accepts attacker-controlled HTTP Host headers. Attackers can send requests to submitIndex.php or ajax.php with arbitrary Host headers to probe internal network hosts and ports, following redirects
Indicators of compromise
- CVE-2026-91966cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-91966