AVideo through commit c91b5975d contains a cross-site request forgery vulnerability in removePoster.php that lacks forbidIfNotPost or forbidIfInvalidToken checks. Attackers can craft malicious image tags to delete authenticated victims' live poster and thumbnail files via GET requests.
Metrics
Affected Vendors & Products
References
History
Thu, 03 Sep 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 03 Sep 2026 11:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | AVideo through commit c91b5975d contains a cross-site request forgery vulnerability in removePoster.php that lacks forbidIfNotPost or forbidIfInvalidToken checks. Attackers can craft malicious image tags to delete authenticated victims' live poster and thumbnail files via GET requests. | |
| Title | AVideo removePoster.php Cross-Site Request Forgery File Deletion | |
| First Time appeared |
Wwbn
Wwbn avideo |
|
| Weaknesses | CWE-352 | |
| CPEs | cpe:2.3:a:wwbn:avideo:-:*:*:*:*:*:*:* | |
| Vendors & Products |
Wwbn
Wwbn avideo |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-03T14:30:23.659Z
Reserved: 2026-09-03T11:04:41.806Z
Link: CVE-2026-85161
Updated: 2026-09-03T14:09:04.001Z
Status : Received
Published: 2026-09-03T13:06:23.127
Modified: 2026-09-03T15:17:37.870
Link: CVE-2026-85161
No data.
OpenCVE Enrichment
Updated: 2026-09-03T14:15:06Z