Cross-Site Request Forgery Vulnerability in AVideo Streaming Software
CVE-2026-85162
7.1HIGH
What is CVE-2026-85162?
A vulnerability in AVideo allows attackers to exploit the lack of protections in the saveLive.php script. This cross-site request forgery (CSRF) flaw enables them to forge requests, potentially overwriting RTMP keys, passwords, and stream titles of authenticated users. As a result, these attackers can hijack live broadcasts, posing a significant threat to user security and the integrity of streaming services.
Affected Version(s)
AVideo 0
