Description
WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a reflected cross-site scripting vulnerability in plugin/Live/confirmLivePassword.php. The script interpolates the unauthenticated GET parameter u (which is not covered by $securityFilter) directly into an <img src="..."> attribute without URL- or HTML-encoding. A remote attacker can craft a link containing a double-quote character in u (with a non-empty key parameter and no valid c parameter) to close the src attribute and inject an additional tag with an onerror handler, executing arbitrary JavaScript in the site's origin in the browser of any user, including an administrator, who opens the link. No patched version was available at the time of the advisory.
Published: 2026-09-11
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Reflected Cross‑Site Scripting (arbitrary JavaScript execution)
Action: Apply Workaround
AI Analysis

Impact

WWBN AVideo includes a reflected cross‑site scripting flaw in plugin/Live/confirmLivePassword.php. The script takes the unauthenticated GET parameter u, which is not sanitized by the security filter, and interpolates it directly into an img src attribute. An attacker can inject a double‑quote and a malicious tag with an onerror handler, causing any browser that loads the crafted link—including administrators—to execute arbitrary JavaScript in the site's origin.

Affected Systems

The vulnerability affects the WWBN AVideo platform, specifically the confirmLivePassword.php file under the Live plugin. Any instance of AVideo built from commit c3edcc274c389816d434acadac07ee78eaf330c1 or any earlier version that has not applied a subsequent patch is susceptible. No specific patch version was available installations running the affected code base remain at risk.

Risk and Exploitability

The CVSS score of 5.3 indicates moderate severity. EPSS information is not available, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is remote: an adversary only needs to craft a URL containing a malicious u parameter and entice a user to click it. Authentication is not required for the vulnerable endpoint. The impact is confined to the victim's browser session and can lead to session hijacking, credential theft, or phishing. Due to the lack of a current public fix, the exploit is theoretically straightforward for attackers who can generate and spread malicious links.

Generated by OpenCVE AI on September 11, 2026 at 14:09 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update AVideo to the latest version once a patch is released
  • Escape or remove the injected double‑quote in the u parameter before it is echoed into the img tag
  • Restrict access to confirmLivePassword.php to authenticated users or move it behind a login page
  • Deploy a Content Security Policy that blocks inline JavaScript to mitigate the effect of any residual XSS
  • Monitor web logs for anomalous request patterns that match the malicious URL structure

Generated by OpenCVE AI on September 11, 2026 at 14:09 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 11 Sep 2026 11:30:00 +0000

Type Values Removed Values Added
Description WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a reflected cross-site scripting vulnerability in plugin/Live/confirmLivePassword.php. The script interpolates the unauthenticated GET parameter u (which is not covered by $securityFilter) directly into an <img src="..."> attribute without URL- or HTML-encoding. A remote attacker can craft a link containing a double-quote character in u (with a non-empty key parameter and no valid c parameter) to close the src attribute and inject an additional tag with an onerror handler, executing arbitrary JavaScript in the site's origin in the browser of any user, including an administrator, who opens the link. No patched version was available at the time of the advisory.
Title WWBN AVideo Reflected XSS via confirmLivePassword.php
First Time appeared Wwbn
Wwbn avideo
Weaknesses CWE-79
CPEs cpe:2.3:a:wwbn:avideo:-:*:*:*:*:*:*:*
Vendors & Products Wwbn
Wwbn avideo
References
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-11T13:59:30.807Z

Reserved: 2026-09-11T10:51:31.662Z

Link: CVE-2026-89240

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-09-11T12:16:53.493

Modified: 2026-09-11T15:21:12.850

Link: CVE-2026-89240

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T18:00:15Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')