CVE-2026-84477: AVideo Stored XSS via Live Schedule Title Description

Published Sep 1, 2026
·
Updated

AVideo Liveschedule::setTitle() and setDescription() store POST input without sanitization, allowing users with streaming permission to inject malicious scripts. Unauthenticated attackers can access remindMe.php to execute stored XSS payloads in victim browsers without requiring authentication.

Affected Software

1 affected component
AVideo

Event History

Sep 1, 2026
CVE Published
via MITRE·10:25 PM
Data Sourced
via MITRE·10:25 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can inject the malicious content?

A user with streaming permission can submit malicious script through the live schedule title or description fields. Exploitation requires that user to be authenticated and able to create or modify the relevant live-schedule content.

2

Who can be affected when the payload is viewed?

Unauthenticated users can reach remindMe.php, where the stored payload may execute in their browser. Victims do not need to authenticate for the XSS payload to be triggered.

3

Does exploitation require victim interaction?

Yes. The supplied vector indicates user interaction is required, meaning a victim must access the affected content or endpoint for the stored script to execute.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203