Vulnerability Description
AVideo through commit c91b5975d contains a cross-site request forgery vulnerability in plugin/Live/saveLive.php that lacks forbidIfNotPost and forbidIfInvalidToken protections. Attackers can craft malicious image tags to overwrite authenticated streamers' RTMP keys, passwords, and titles, hijacking live broadcasts.
CVSS Score
MEDIUM
Related Weaknesses (CWE)
References
- https://github.com/WWBN/AVideo/security/advisories/GHSA-6jj8-2953-6frf
- https://www.vulncheck.com/advisories/avideo-through-c91b5975d-csrf-via-savelive-
- https://github.com/WWBN/AVideo/security/advisories/GHSA-6jj8-2953-6frf
FAQ
What is CVE-2026-85162?
CVE-2026-85162 is a vulnerability with a CVSS score of 6.5 (MEDIUM). AVideo through commit c91b5975d contains a cross-site request forgery vulnerability in plugin/Live/saveLive.php that lacks forbidIfNotPost and forbidIfInvalidToken protections. Attackers can craft mal...
How severe is CVE-2026-85162?
CVE-2026-85162 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-85162?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.