CVE-2026-56342 | AVideo up to 27.0 Network Configuration plugin/Live/test.php isSSRFSafeURL statsURL server-side request forgery (GHSA-wxjx-r2j2-96fx / EUVD-2026-38131)
A vulnerability classified as critical has been found in AVideo up to 27.0. This affects the function isSSRFSafeURL of the file plugin/Live/test.php of the component Network Configuration Handler. Performing a manipulation of the argument statsURL results in server-side request forgery.
This vulnerability is reported as CVE-2026-56342. The attack is possible to be carried out remotely. No exploit exists.