PT-2026-84990 · Avideo · Avideo

·

CVE-2026-85158

·

Published

2026-09-03

·

Updated

2026-09-03

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions AVideo versions prior to commit c91b5975d
Description A reflected cross-site scripting issue exists in the 'videoEmbeded.php' endpoint. The application echoes the link parameter within an HTML comment without proper escaping. An attacker can bypass the comment by injecting the --> sequence, allowing the execution of arbitrary JavaScript in the victim's browser when they visit a specially crafted embed URL.
Recommendations Update AVideo to a version that includes commit c91b5975d or later.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-85158

Affected Products

Avideo