Stored XSS Vulnerability in AVideo Live Streaming Tool
CVE-2026-84477
5.1MEDIUM
What is CVE-2026-84477?
AVideo Live Stream contains a vulnerability that allows users with streaming permission to execute stored XSS attacks through unsanitized POST data in Live_schedule::setTitle() and setDescription(). Unauthenticated attackers can exploit the forgetMe.php functionality to execute malicious scripts in victim browsers, significantly compromising the security and integrity of the affected system.
Affected Version(s)
AVideo 0 <= 29.0
