Impact
WWBN AVideo up to version 29.2.0 has a stored cross‑site scripting flaw that lets an upload‑enabled user set a malicious trailer1 URL. The data is rendered unescaped in the YouPHPFlix2 templates and channel playlists, allowing attackers to break out of JavaScript context such as onclick attributes or iframe src parameters and run arbitrary code in the browsers of any viewer. This could be used to steal session cookies, deface pages, or launch phishing attacks against users who view the compromised video.
Affected Systems
Vendors: WWBN AVideo. Products: the AVideo platform, specifically version 29.2.0 and earlier where the trailer1 injection is present. Attack can affect any instance of this software running those versions.
Risk and Exploitability
With a CVSS score of 9.3 the vulnerability is considered critical. The exploit requires only that the attacker has upload rights on the affected instance, which is common in many installations. Because the issue is stored, the malicious payload is delivered to all viewers until removed, meaning a single compromised upload can continue to affect users indefinitely. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, but the high severity recommends immediate remediation.
OpenCVE Enrichment