PT-2026-84990 · Avideo · Avideo
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
AVideo versions prior to commit c91b5975d
Description
A reflected cross-site scripting issue exists in the 'videoEmbeded.php' endpoint. The application echoes the
link parameter within an HTML comment without proper escaping. An attacker can bypass the comment by injecting the --> sequence, allowing the execution of arbitrary JavaScript in the victim's browser when they visit a specially crafted embed URL.Recommendations
Update AVideo to a version that includes commit c91b5975d or later.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Avideo