CVE-2026-84477
published 2026-09-01CVE-2026-84477: AVideo Live_schedule::setTitle() and setDescription() store POST input without sanitization, allowing users with streaming permission to inject malicious…
PriorityP431medium5.4CVSS 3.1
AVNACLPRLUIRSCCLILAN
EPSS
0.29%
19.9th percentile
AVideo Live_schedule::setTitle() and setDescription() store POST input without sanitization, allowing users with streaming permission to inject malicious scripts. Unauthenticated attackers can access remindMe.php to execute stored XSS payloads in victim browsers without requiring authentication.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| wwbn | avideo | <= 29.0 | — |
CVSS provenance
nvdv3.15.4MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
nvdv4.05.1MEDIUMCVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
WWBN AVideo up to 29.0 Live_schedule remindMe.php Live_schedule::setTitle cross site scripting (EUVD-2026-69719)
vuldb·2026-09-02·CVSS 5.4
CVE-2026-84477 [MEDIUM] WWBN AVideo up to 29.0 Live_schedule remindMe.php Live_schedule::setTitle cross site scripting (EUVD-2026-69719)
A vulnerability classified as problematic was found in WWBN AVideo up to 29.0. This vulnerability affects the function Live_schedule::setTitle of the file remindMe.php of the component Live_schedule. The manipulation results in cross site scripting.
This vulnerability is known as CVE-2026-84477. It is possible to launch the attack remotely. No exploit is available.
GHSA
AVideo Live_schedule::setTitle() and setDescription() store POST input without sanitization, allowing users with streaming permission to inject malicious scripts.
ghsa_unreviewed·2026-09-02
CVE-2026-84477 [MEDIUM] CWE-79 AVideo Live_schedule::setTitle() and setDescription() store POST input without sanitization, allowing users with streaming permission to inject malicious scripts.
AVideo Live_schedule::setTitle() and setDescription() store POST input without sanitization, allowing users with streaming permission to inject malicious scripts. Unauthenticated attackers can access remindMe.php to execute stored XSS payloads in victim browsers without requiring authentication.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-09-01
Published