PT-2026-84991 · Avideo · Avideo

·

CVE-2026-85159

·

Published

2026-09-03

·

Updated

2026-09-03

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions AVideo versions prior to commit c91b5975d
Description A reflected cross-site scripting issue exists in the 'userLogin.php' endpoint. The cancelUri parameter is echoed within an href attribute after the isSafeRedirectURL() function validates only the protocol and fails to sanitize HTML characters. This allows unauthenticated attackers to inject event handlers using relative URLs containing embedded quotes, leading to the execution of arbitrary JavaScript when a user interacts with the Cancel button.
Recommendations Update AVideo to a version beyond commit c91b5975d. As a temporary mitigation, restrict or avoid using the cancelUri parameter in the 'userLogin.php' endpoint.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-85159

Affected Products

Avideo