PT-2026-84994 · Avideo · Avideo

·

CVE-2026-85162

·

Published

2026-09-03

·

Updated

2026-09-03

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions AVideo versions prior to commit c91b5975d
Description Cross-site request forgery (CSRF) occurs in the 'plugin/Live/saveLive.php' endpoint due to the absence of forbidIfNotPost and forbidIfInvalidToken protections. This allows attackers to use malicious image tags to overwrite the RTMP keys, passwords, and titles of authenticated streamers, enabling the hijacking of live broadcasts.
Recommendations Update AVideo to a version beyond commit c91b5975d.

Exploit

Fix

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-85162

Affected Products

Avideo