Description
WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a stored cross-site scripting vulnerability in UserGroups::setGroup_name() that fails to sanitize group_name input. Administrators with canAdminUserGroups permission can inject malicious HTML and JavaScript that executes in the browser when other administrators access the user manager interface.
Published: 2026-09-11
Score: 9.2 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Stored Cross‑Site Scripting
Action: Immediate Patch
AI Analysis

Impact

A stored cross‑site scripting vulnerability exists in AVideo’s UserGroups::setGroup_name() where the group_name field is not properly sanitized. Administrators with canAdminUserGroups permission can inject malicious HTML and JavaScript that executes in the browser of other administrators when they open the user manager interface. This flaw allows an attacker to execute arbitrary client‑side code, potentially hijacking admin sessions, manipulating UI, or collecting information while an administrator is logged in.

Affected Systems

The affected product is WWBN AVideo. No specific version information is provided, so any installation that uses the vulnerable UserGroups implementation is potentially impacted.

Risk and Exploitability

The CVSS base score is 9.2, indicating a high‑severity flaw. The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog. Because the flaw requires administrator privileges, the likely attack vector is through an authenticated session where an attacker can create or modify a user group. Once the malicious script runs in their browser, giving the attacker client‑side execution capabilities.

Generated by OpenCVE AI on September 11, 2026 at 14:07 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Install the latest AVideo release that addresses the stored XSS in UserGroups::setGroup_name.
  • Remove only trusted administrators.
  • Implement proper input validation or output encoding for group names to prevent XSS in future releases.

Generated by OpenCVE AI on September 11, 2026 at 14:07 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 11 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 11 Sep 2026 11:30:00 +0000

Type Values Removed Values Added
Description WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a stored cross-site scripting vulnerability in UserGroups::setGroup_name() that fails to sanitize group_name input. Administrators with canAdminUserGroups permission can inject malicious HTML and JavaScript that executes in the browser when other administrators access the user manager interface.
Title WWBN AVideo Stored XSS via UserGroups setGroup_name
First Time appeared Wwbn
Wwbn avideo
Weaknesses CWE-79
CPEs cpe:2.3:a:wwbn:avideo:-:*:*:*:*:*:*:*
Vendors & Products Wwbn
Wwbn avideo
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:N'}

cvssV4_0

{'score': 9.2, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-11T12:42:57.021Z

Reserved: 2026-09-11T10:51:31.663Z

Link: CVE-2026-89243

cve-icon Vulnrichment

Updated: 2026-09-11T12:42:51.924Z

cve-icon NVD

Status : Deferred

Published: 2026-09-11T12:16:53.960

Modified: 2026-09-11T15:21:12.850

Link: CVE-2026-89243

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-12T10:30:13Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')