MEDIUM
AVideo userLogin.php Reflected XSS via error parameter
Published Sep 4, 2026
5.3
MEDIUMCVSS 4.0
EPSS 0.29%
Description
AVideo through commit c91b5975d contains a reflected cross-site scripting vulnerability in userLogin.php that allows unauthenticated attackers to inject arbitrary JavaScript by closing the script tag with </script>. Attackers can craft a malicious URL with an error parameter containing script breakout sequences to execute arbitrary JavaScript in the victim's browser context on the login page.
Affected products
-
Affected
- ≥ 0, ≤ c91b5975d
No data.
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (3)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-71000 Advisory
- https://github.com/WWBN/AVideo/security/advisories/GHSA-v654-6qw8-pc33 exploitvendor-advisory
- https://www.vulncheck.com/advisories/avideo-userlogin-php-reflected-xss-via-error-parameter third-party-advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-71000 | Advisory | |
| https://github.com/WWBN/AVideo/security/advisories/GHSA-v654-6qw8-pc33 | exploitvendor-advisory | |
| https://www.vulncheck.com/advisories/avideo-userlogin-php-reflected-xss-via-error-parameter | third-party-advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulnCheck
Published Sep 4, 2026
Updated Sep 4, 2026
Reserved Sep 4, 2026
Link CVE-2026-85577
CISA Vulnrichment
Updated Sep 4, 2026
Red Hat
No data
GitHub
No data