PT-2026-104642 · Avideo · Avideo
CVSS v4.0
9.3
Critical
| Vector | AV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N |
Name of the Vulnerable Software and Affected Versions
AVideo versions prior to 29.2.0
Description
A stored cross-site scripting issue exists where users with upload permissions can inject scripts by providing a malicious URL for the video trailer. This value is rendered without proper escaping in YouPHPFlix templates and channel playlists, enabling attackers to break out of
onclick strings or iframe src attributes to execute JavaScript in the browsers of other users.Recommendations
Update to a version newer than 29.2.0.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Avideo