PT-2026-29366 · Avideo+1 · Avideo+1

Adrgs

·

Published

2026-03-31

·

Updated

2026-03-31

·

CVE-2026-34739

CVSS v3.1

6.1

Medium

AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions AVideo versions prior to 26.0
Description AVideo is an open source video platform. Versions 26.0 and earlier have a reflected cross-site scripting (XSS) issue in the User Location plugin’s testIP.php page. The ip request parameter is directly included in an HTML input element without proper output encoding. This allows an attacker to inject arbitrary HTML and JavaScript through a specially crafted URL. While the page is limited to administrator users, the SameSite=None cookie configuration enables cross-origin exploitation. An attacker can trick an administrator into clicking a malicious link, which then executes JavaScript within their authenticated session. The vulnerable parameter is ip.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

XSS

Weakness Enumeration

Related Identifiers

CVE-2026-34739

Affected Products

Avideo
User Location