Beveiligingsadvies

CVE-2026-89252

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2026-09-11 11:15:30
Laatst bijgewerkt 2026-09-11 11:15:30
Toegewezen door VulnCheck
CVSS-score 7.1
Status PUBLISHED

Beschrijving

AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to verify ownership in addLiveLink.php when updating LiveLinks, allowing authenticated users to modify other users' links. A canStream user can overwrite another user's LiveLink HLS source and metadata by supplying an existing linkId, redirecting viewers to attacker-controlled media.