CVE-2025-34439
MEDIUMAVideo < 20.1 - Open Redirect via cancelUri Parameter
Title source: llmDescription
AVideo versions prior to 20.1 are vulnerable to an open redirect flaw due to missing validation of the cancelUri parameter during user login. An attacker can craft a link to redirect users to arbitrary external sites, enabling phishing attacks.
References (4)
Core 4
Core References
Third Party Advisory third-party-advisory
https://www.vulncheck.com/advisories/avideo-open-redirect-via-canceluri-parameter
Various Sources technical-description
exploit
https://chocapikk.com/posts/2025/avideo-security-vulnerabilities/
Scores
CVSS v3
6.1
EPSS
0.0016
EPSS Percentile
5.6%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-601
Status
published
Products (2)
World Wide Broadcast Network/AVideo
< 20.1
wwbn/avideo
< 20.0
Published
Dec 17, 2025
Tracked Since
Feb 18, 2026