Impact
WWBN AVideo contains an XML injection flaw in plugin/AD_Server/VMAP.php. The script returns an XML response that embeds values from the $_REQUEST['vmaps'] parameter without encoding. An attacker can craft a payload that injects arbitrary <vmap:AdBreak> and <vmap:AdTagURI> nodes into the XML, causing the player’s IMA loader to request attacker‑supplied ad URLs and triggering ad injection and cross‑origin requests from the victim’s playback session.
Affected Systems
All publicly accessible instances of WWBN AVideo with the AD_Server plugin enabled that contain code at or before commit c3edcc274c389816d434acadac07ee78eaf330c1 are vulnerable; no explicit version numbers are reported, so earlier commits are affected until the fix is applied. The vulnerability resides in plugin/AD_Server/VMAP.php and is reachable without authentication.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity. The EPSS score is not available, and the vulnerability is not listed in CISA's KEV catalog. It is reachable without authentication and relies on an attacker‑controlled input that is reflected without encoding, making exploitation possible in exposed environments. The impact includes undesired or malicious ad injection and potential cross‑origin data leakage or privacy violations.
OpenCVE Enrichment