Loading market data...
← Back to CVE feed

CVE-2026-85161

MEDIUM CVSS 4.3 View on NVD ↗

Description

AVideo through commit c91b5975d contains a cross-site request forgery vulnerability in removePoster.php that lacks forbidIfNotPost or forbidIfInvalidToken checks. Attackers can craft malicious image tags to delete authenticated victims' live poster and thumbnail files via GET requests.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
Published: Sep 03, 2026 13:06 UTC Modified: Sep 03, 2026 15:17 UTC