Description
WWBN AVideo at commit c3edcc274c389816d434acadac07ee78eaf330c1 and earlier contains an XML injection vulnerability in plugin/AD_Server/VMAP.php, which is reachable without authentication when the AD_Server plugin is enabled. The script emits Content-Type: application/xml and writes the timeOffset and idTag values returned by AD_Server::getVMAPSFromRequest() directly into VMAP attributes without encoding. Those values originate from the base64- and JSON-decoded $_REQUEST['vmaps'] parameter, which is not covered by $securityFilter in objects/security.php. A remote attacker can craft a vmaps value (containing a non-empty VAST.campaing entry) and induce a user to open the resulting VMAP URL or a video page using it, injecting arbitrary <vmap:AdBreak> and <vmap:AdTagURI>/AdSource nodes into the generated XML. The player's IMA path (afterVideoJS -> PlayerSkins::setIMAADTag) then requests the attacker-supplied ad URLs, resulting in ad injection and cross-origin requests from the victim's playback session. The issue was unfixed at the time of reporting.
Published: 2026-09-11
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: XML injection permits arbitrary ad tag injection and triggers cross‑origin requests from playback sessions
Action: Patch Now
AI Analysis

Impact

WWBN AVideo contains an XML injection flaw in plugin/AD_Server/VMAP.php. The script returns an XML response that embeds values from the $_REQUEST['vmaps'] parameter without encoding. An attacker can craft a payload that injects arbitrary <vmap:AdBreak> and <vmap:AdTagURI> nodes into the XML, causing the player’s IMA loader to request attacker‑supplied ad URLs and triggering ad injection and cross‑origin requests from the victim’s playback session.

Affected Systems

All publicly accessible instances of WWBN AVideo with the AD_Server plugin enabled that contain code at or before commit c3edcc274c389816d434acadac07ee78eaf330c1 are vulnerable; no explicit version numbers are reported, so earlier commits are affected until the fix is applied. The vulnerability resides in plugin/AD_Server/VMAP.php and is reachable without authentication.

Risk and Exploitability

The CVSS score of 5.3 indicates moderate severity. The EPSS score is not available, and the vulnerability is not listed in CISA's KEV catalog. It is reachable without authentication and relies on an attacker‑controlled input that is reflected without encoding, making exploitation possible in exposed environments. The impact includes undesired or malicious ad injection and potential cross‑origin data leakage or privacy violations.

Generated by OpenCVE AI on September 11, 2026 at 14:35 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest WWBN AVideo release that contains the fix once it is available.
  • If the AD_Server plugin is not required, disable it entirely.
  • Restrict access to plugin/AD_Server/VMAP.php to authenticated users only.
  • Implement input validation and XML‑encoding for the $_REQUEST['vmaps'] parameter or extend the $securityFilter configuration to cover this endpoint.

Generated by OpenCVE AI on September 11, 2026 at 14:35 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 11 Sep 2026 11:30:00 +0000

Type Values Removed Values Added
Description WWBN AVideo at commit c3edcc274c389816d434acadac07ee78eaf330c1 and earlier contains an XML injection vulnerability in plugin/AD_Server/VMAP.php, which is reachable without authentication when the AD_Server plugin is enabled. The script emits Content-Type: application/xml and writes the timeOffset and idTag values returned by AD_Server::getVMAPSFromRequest() directly into VMAP attributes without encoding. Those values originate from the base64- and JSON-decoded $_REQUEST['vmaps'] parameter, which is not covered by $securityFilter in objects/security.php. A remote attacker can craft a vmaps value (containing a non-empty VAST.campaing entry) and induce a user to open the resulting VMAP URL or a video page using it, injecting arbitrary <vmap:AdBreak> and <vmap:AdTagURI>/AdSource nodes into the generated XML. The player's IMA path (afterVideoJS -> PlayerSkins::setIMAADTag) then requests the attacker-supplied ad URLs, resulting in ad injection and cross-origin requests from the victim's playback session. The issue was unfixed at the time of reporting.
Title WWBN AVideo XML Injection via plugin/AD_Server/VMAP.php
First Time appeared Wwbn
Wwbn avideo
Weaknesses CWE-91
CPEs cpe:2.3:a:wwbn:avideo:-:*:*:*:*:*:*:*
Vendors & Products Wwbn
Wwbn avideo
References
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-15T16:11:31.860Z

Reserved: 2026-09-11T10:51:31.663Z

Link: CVE-2026-89247

cve-icon Vulnrichment

Updated: 2026-09-15T16:11:27.136Z

cve-icon NVD

Status : Deferred

Published: 2026-09-11T12:16:54.573

Modified: 2026-09-15T17:17:34.703

Link: CVE-2026-89247

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T16:45:14Z

Weaknesses
  • CWE-91

    XML Injection (aka Blind XPath Injection)