← Terug naar overzicht

WWBN AVideo through commit c91b5975d is affected by a server-side request forgery (SSRF) vulnerability in the set_api_userImages API endpoint. The vulnerability exists because the endpoint fails to validate the profileImg and backgroundImg URL parameters before fetching them. Authenticated API clients can exploit this flaw by supplying internal URLs, enabling them to access cloud metadata services or internal network resources. The fetched responses are written to publicly accessible web paths, allowing attackers to subsequently retrieve sensitive data. This represents a significant risk in cloud-hosted deployments where metadata endpoints such as AWS IMDSv1 may be reachable. Exploitation requires authentication but no elevated privileges beyond a standard API client. The issue has been documented in GitHub Security Advisories and VulnCheck. No patch version is specified beyond the affected commit reference.

Affected products

  • WWBN AVideo

Related CVE's

  • CVE-2026-85164

Categories

  • Cloud & Virtualization
  • Web Technologies