Impact
The vulnerability is a stored cross‑site scripting flaw that allows authenticated uploaders to insert malicious code by submitting doubly‑encoded HTML entities in video titles. The application’s safeString() routine strips tags before decoding entities, and this process is executed twice—first during setTitle() and again during save()—allowing the payload to persist in the database and later be rendered on trending, gallery, embed, and playlist pages. If executed, the script runs in the context of any user viewing those pages, enabling defacement, cookie theft, or session hijacking.
Affected Systems
All releases of the WWBN AVideo web application from version 12.4 through 29.2.0 are impacted. Deployments within this version range that provide upload privileges to users are at risk, because any authenticated uploader can exploit the flaw. Administrators should confirm whether their instances include these versions and assess the scope of upload permissions.
Risk and Exploitability
With a CVSS score of 9.3, the flaw is classified as High severity. No EPSS score is available, and it is not listed in the CISA KEV catalog, but the absence of those metrics does not lessen the danger. The likely attack vector is stored XSS via double‑encoded video titles, requiring the attacker to possess valid uploader credentials or to compromise an account. Once injected, the payload can execute when any user visits the page that displays the title, giving attackers broad opportunities to execute arbitrary JavaScript in the victim’s browser.
OpenCVE Enrichment