AVideo through commit c91b5975d contains a cross-site request forgery and path traversal vulnerability in stopLive.php that allows attackers to delete directories by exploiting missing token validation and unsanitized key parameter concatenation. Attackers can craft an image tag with a traversal payload like key=../../videos to trigger recursive deletion of the videos directory when an admin visits a malicious page.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-09-03 13:06
Updated : 2026-09-08 20:18
NVD link : CVE-2026-85160
Mitre link : CVE-2026-85160
CVE.ORG link : CVE-2026-85160
JSON object : View
Products Affected
No product.
CWE
CWE-73
External Control of File Name or Path
