Description
WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a CSV formula injection vulnerability in the myComments.download.php endpoint that fails to sanitize spreadsheet formula prefixes in comment text. Authenticated users can inject formulas starting with =, +, -, or @ characters that execute when administrators or video owners open the exported CSV file in spreadsheet applications.
Published: 2026-09-11
Score: 5.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Spreadsheet Formula Injection
Action: Apply Patch
AI Analysis

Impact

WWBN AVideo contains a CSV formula injection flaw in the myComments.download.php endpoint comment text, allowing an attacker to insert spreadsheet formulas that start with '=', '+', '-', or '@'. When an administrator or video owner exports the comments as CSV and opens the file in a spreadsheet application, the embedded formula executes, potentially exposing or manipulating data. This weakness is a classic CSV formula injection (CWE-1236).

Affected Systems

The affected product is releases prior to commit c3edcc274c389816d434acadac07ee78eaf330c1. Any deployment that has not applied this update is susceptible. Administrators and video owners who export comment data are the ones who could trigger the payload in the myComments.download.php endpoint of WWBN AVideo, allowing an authenticated user to insert comment text that begins with spreadsheet formula prefixes (=, +, -, @). When an administrator or video owner exports comments as a CSV file and opens it in a spreadsheet, the injected formula is executed, potentially exposing sensitive data. The weakness is a classic CSV formula injection (CWE-1236).

Risk and Exploitability

The CVSS score of 5.1 indicates a medium severity with an attack vector that requires user interaction to trigger the injection. The exploit is limited to authenticated users who can create or edit comments; no publicly exploitable remote service is required. Because the vulnerability does not automatically grant attackers full control over the system, the risk is primarily local. Current EPSS data is not available, and the issue is not listed in the CISA KEV catalog. Compromised administrators could potentially expose sensitive data within the spreadsheet, leading to potential data exfiltration.

Generated by OpenCVE AI on September 11, 2026 at 14:06 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the vendor’s patch that addresses CSV formula injection by upgrading WWBN AVideo to a release that includes commit c3edcc274c389816d434acadac07ee78eaf330c1.
  • Sanitize or escape comment text before writing to CSV: strip leading =, +, -, @ characters or prefix the output with a harmless character such as a tab or space.
  • Disable or restrict the CSV export feature for owners until the patch is applied.

Generated by OpenCVE AI on September 11, 2026 at 14:06 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 11 Sep 2026 11:30:00 +0000

Type Values Removed Values Added
Description WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a CSV formula injection vulnerability in the myComments.download.php endpoint that fails to sanitize spreadsheet formula prefixes in comment text. Authenticated users can inject formulas starting with =, +, -, or @ characters that execute when administrators or video owners open the exported CSV file in spreadsheet applications.
Title WWBN AVideo CSV Formula Injection via myComments.download.php
First Time appeared Wwbn
Wwbn avideo
Weaknesses CWE-1236
CPEs cpe:2.3:a:wwbn:avideo:-:*:*:*:*:*:*:*
Vendors & Products Wwbn
Wwbn avideo
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'}

cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-11T18:20:45.261Z

Reserved: 2026-09-11T10:51:31.663Z

Link: CVE-2026-89246

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-09-11T12:16:54.423

Modified: 2026-09-11T19:17:47.320

Link: CVE-2026-89246

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T21:30:03Z

Weaknesses
  • CWE-1236

    Improper Neutralization of Formula Elements in a CSV File