Description
AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a stored cross-site scripting vulnerability in the YPTWallet plugin where user-supplied CryptoWallet values are base64-encoded but not HTML-escaped before storage in wallet_log.information. Administrators viewing pending withdrawal requests in pendingRequests.php execute the stored markup in their session, allowing attackers to perform administrative actions via same-origin fetch requests.
Published: 2026-09-11
Score: 9.3 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Stored XSS allowing administrators to perform privileged actions
Action: Patch Now
AI Analysis

Impact

AVVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a stored cross‑site scripting vulnerability in the YPTWallet plugin. User‑supplied CryptoWallet values are base64‑encoded but not HTML‑escaped before storage in a wallet_log.information entry. When an administrator later opens pendingRequests.php to review withdrawal requests, the stored markup is executed in the admin’s browser session, permitting the attacker to perform administrative actions via same‑origin fetch requests.

Affected Systems

The flaw resides in the AVideo platform, provided by WWBN, specifically in the YPTWallet plugin as shipped in the main branch. The affected code can be found in commit c3edcc274c389816d434acadac07ee78eaf330c1. No specific version range is listed; however, any installation that includes this commit or later without the patch is impacted. The vendor is WWBN and the product is AVideo, database.

Risk and Exploitability

This issue carries a CVSS score of 9.3, indicating critical severity. The EPSS score is not available, and the vulnerability is not currently listed in the CISA KEV catalog. Exploitation requires the attacker to supply a an administrator views the pending withdrawal page; the attack vector is therefore internal to the administrative interface but the initial input can be supplied externally if the plugin accepts user input from outside the protected area. Attackers can achieve privilege escalation to any administrative function that relies on same‑origin requests, potentially compromising the entire platform.

Generated by OpenCVE AI on September 11, 2026 at 14:26 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest AVideo release or patch that sanitizes CryptoWallet values before storage
  • If a patch is unavailable, modify the YPTWallet code to escape all user‑supplied input when storing or rendering wallet_log.information
  • Restrict access to pendingRequests.php to trusted accounts and remove the ability to render arbitrary data without sanitization

Generated by OpenCVE AI on September 11, 2026 at 14:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 11 Sep 2026 11:30:00 +0000

Type Values Removed Values Added
Description AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a stored cross-site scripting vulnerability in the YPTWallet plugin where user-supplied CryptoWallet values are base64-encoded but not HTML-escaped before storage in wallet_log.information. Administrators viewing pending withdrawal requests in pendingRequests.php execute the stored markup in their session, allowing attackers to perform administrative actions via same-origin fetch requests.
Title AVideo YPTWallet Stored XSS via CryptoWallet Configuration
First Time appeared Wwbn
Wwbn avideo
Weaknesses CWE-79
CPEs cpe:2.3:a:wwbn:avideo:-:*:*:*:*:*:*:*
Vendors & Products Wwbn
Wwbn avideo
References
Metrics cvssV3_1

{'score': 8.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N'}

cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-11T20:29:58.576Z

Reserved: 2026-09-11T10:51:59.214Z

Link: CVE-2026-89249

cve-icon Vulnrichment

Updated: 2026-09-11T17:43:27.649Z

cve-icon NVD

Status : Deferred

Published: 2026-09-11T12:16:54.890

Modified: 2026-09-11T21:17:57.147

Link: CVE-2026-89249

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T18:30:13Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')