Skip to content

Menu
  • Home
Menu

CVE-2026-84208 – AVideo User_Location Plugin Unauthenticated SQL Injection

Posted on September 2, 2026
CVE ID :CVE-2026-84208

Published : Sept. 1, 2026, 11:17 p.m. | 1 hour, 19 minutes ago

Description :AVideo through version 29.0 contains an unauthenticated SQL injection vulnerability in the User_Location plugin’s regions.json.php and cities.json.php endpoints. The country and region GET parameters are passed directly into SQL queries without escaping or prepared statement binding, allowing unauthenticated attackers to execute UNION-based SQL injection to read arbitrary database contents including password hashes and sensitive data.

Severity: 8.7 | HIGH

Visit the link for more details, such as CVSS details, affected products, timeline, and more…

Post Views: 1

Site map

  • About Us
  • Privacy Policy
  • Terms & Conditions of Use
©2026 | Design: Newspaperly WordPress Theme