PT-2026-84994 · Avideo · Avideo
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
AVideo versions prior to commit c91b5975d
Description
Cross-site request forgery (CSRF) occurs in the 'plugin/Live/saveLive.php' endpoint due to the absence of
forbidIfNotPost and forbidIfInvalidToken protections. This allows attackers to use malicious image tags to overwrite the RTMP keys, passwords, and titles of authenticated streamers, enabling the hijacking of live broadcasts.Recommendations
Update AVideo to a version beyond commit c91b5975d.
Exploit
Fix
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Avideo