Description
WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a reflected cross-site scripting vulnerability in confirmLivePassword.php that copies REQUEST_URI into a form action attribute without encoding. Attackers can craft a malicious URL with a quote character to break out of the action attribute and inject event handlers that execute in the victim's browser within the site origin.
Published: 2026-09-11
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Reflected Cross‑Site Scripting
Action: Apply Patch
AI Analysis

Impact

WWBN AVideo includes a reflected cross‑site scripting flaw in the confirmLivePassword.php page. The code copies REQUEST_URI can embed a quote character in a malicious URL to break out of the attribute context and inject JavaScript event handlers that run in the victim’s browser while staying within the site origin. The weakness maps to CWE‑79, a vulnerability that allows attackers to execute client‑side scripts in the context of the affected site.

Affected Systems

The affected vendor is WWBN, with the product name AVideo. No specific version information is listed in the CVE, so any deployment of AVideo that includes the confirmLivePassword.php script before the fix is potentially vulnerable.

Risk and Exploitability

The CVSS score of 5.3 indicates a moderate impact level. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, indicating that no publicly disclosed exploits are known at this time. Attackers can exploit this by crafting a malicious URL that points to confirmLivePassword.php, which the victim clicks or visits, causing the injected script to run within the site origin. The risk is confined to the user’s browser session and does not directly compromise the server.

Generated by OpenCVE AI on September 11, 2026 at 14:36 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest AVideo release that addresses the reflected XSS in confirmLivePassword.php.
  • If an update is not immediately available, sanitize or URL‑encode the REQUEST_URI before inserting it into form action attributes to prevent quote injection.
  • Implement additional client‑side XSS defenses such as Content Security Policy or output encoding to mitigate the impact of any residual injection.

Generated by OpenCVE AI on September 11, 2026 at 14:36 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 11 Sep 2026 11:30:00 +0000

Type Values Removed Values Added
Description WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a reflected cross-site scripting vulnerability in confirmLivePassword.php that copies REQUEST_URI into a form action attribute without encoding. Attackers can craft a malicious URL with a quote character to break out of the action attribute and inject event handlers that execute in the victim's browser within the site origin.
Title WWBN AVideo Reflected XSS via confirmLivePassword.php
First Time appeared Wwbn
Wwbn avideo
Weaknesses CWE-79
CPEs cpe:2.3:a:wwbn:avideo:-:*:*:*:*:*:*:*
Vendors & Products Wwbn
Wwbn avideo
References
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-11T19:19:40.565Z

Reserved: 2026-09-11T10:51:31.662Z

Link: CVE-2026-89241

cve-icon Vulnrichment

Updated: 2026-09-11T19:19:14.871Z

cve-icon NVD

Status : Deferred

Published: 2026-09-11T12:16:53.650

Modified: 2026-09-11T20:19:23.087

Link: CVE-2026-89241

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T16:45:14Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')