Back

MEDIUM

AVideo userLogin.php Reflected XSS via error parameter

Published Sep 4, 2026

Description

AVideo through commit c91b5975d contains a reflected cross-site scripting vulnerability in userLogin.php that allows unauthenticated attackers to inject arbitrary JavaScript by closing the script tag with </script>. Attackers can craft a malicious URL with an error parameter containing script breakout sequences to execute arbitrary JavaScript in the victim's browser context on the login page.

Affected products

Remediation

No remediation recorded yet.

References (3)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner VulnCheck
Published Sep 4, 2026
Updated Sep 4, 2026
Reserved Sep 4, 2026

CISA Vulnrichment

Updated Sep 4, 2026

NVD

Status Deferred
Modified Sep 8, 2026

Red Hat

No data

ENISA EUVD

Assigner VulnCheck
Published Sep 4, 2026
Updated Sep 4, 2026

GitHub

No data