THREAT OPS › Threat News › [NVD] CVE-2026-85159 (MEDIUM 5.4) — AVideo through commit c91b5975d contains a reflected cross-site scripting vulnerability in userLogin.php where the cancelUri parameter is echoed in an href attribute after isSafeRedirectURL checks protocol only, not HTML characters. Unauthenticated attackers can inject event hand
[NVD] CVE-2026-85159 (MEDIUM 5.4) — AVideo through commit c91b5975d contains a reflected cross-site scripting vulnerability in userLogin.php where the cancelUri parameter is echoed in an href attribute after isSafeRedirectURL checks protocol only, not HTML characters. Unauthenticated attackers can inject event hand
CVE-2026-85159 CVSS: 5.4 MEDIUM Published: 2026-09-03T13:06:22.820
AVideo through commit c91b5975d contains a reflected cross-site scripting vulnerability in userLogin.php where the cancelUri parameter is echoed in an href attribute after isSafeRedirectURL checks protocol only, not HTML characters. Unauthenticated attackers can inject event handlers via relative URLs with embedded quotes to execu
MITRE ATT&CK techniques
- JavaScriptT1059.007
Indicators of compromise
- CVE-2026-85159cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-85159