Medium severity4.3NVD Advisory· Published Sep 3, 2026
CVE-2026-85161
CVE-2026-85161
Description
AVideo through commit c91b5975d contains a cross-site request forgery vulnerability in removePoster.php that lacks forbidIfNotPost or forbidIfInvalidToken checks. Attackers can craft malicious image tags to delete authenticated victims' live poster and thumbnail files via GET requests.
Affected products
1Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.