Description
WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a stored cross-site scripting vulnerability in the user 'donationLink' profile field. User::setDonationLink() (objects/user.php) stores the value and save() validates it only with filter_var(..., FILTER_VALIDATE_URL), which accepts strings such as http://evil.example/"onmouseover=alert(document.domain)//, while getDonationLink() applies only strip_tags() and does not encode double quotes. plugin/CustomizeUser/actionButton.php echoes the value unencoded into an <a href="..."> attribute, and that button is included from view/modeYoutubeBottom.php on the watch page when the CustomizeUser option allowDonationLink is enabled. An authenticated user who updates their own profile via objects/userUpdate.json.php can therefore break out of the href attribute and inject an event handler that executes JavaScript in the browser of any visitor—including an administrator—who views the attacker's videos and interacts with (for example, hovers over) the donation button. The issue was unfixed at the time of reporting.
Published: 2026-09-11
Score: 9.3 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Stored XSS that can execute arbitrary JavaScript in the browser of any viewer when the donation button is displayed
Action: Patch
AI Analysis

Impact

The vulnerability is a stored cross‑site scripting flaw in the donationLink field of the AVideo platform. The field validator uses FILTER_VALIDATE_URL, which such as http://evil.example/"onmouseover=alert(document.domain)//. When the user retrieves the field, strip_tags removes any tags but does not encode double quotes, and plugin/ an <a href="..."></a> attribute. An authenticated user can set a malicious link in their profile via the userUpdate.json.php endpoint, and the malformed link will later be rendered in the donation button on any video that the user uploads. When a viewer—including administrators—visits the video and interacts in the viewer’s browser. This flaw allows the attacker to run arbitrary scripts in the context of any user who views the video.

Affected Systems

The flaw resides in the AVideo platform released by WWBN. It affects any installation that contains the code present in the commit c3edcc274c389816d434acadac07ee78eaf330c1. No specific product version is listed, commit or later without a proper fix are vulnerable.

Risk and Exploitability

The CVSS score of 9.3 indicates a critical severity. The attack requires only authenticated access to the user’s own profile to store the malicious link. Once stored, all users who view that user’s videos and interact with the donation button are exposed to the injected script. EPSS data is not available and the vulnerability is not listed in CISA KEV, but the high CVSS, low exploitation barrier, and broad impact scope make the risk substantial in an environment where the feature is enabled.

Generated by OpenCVE AI on September 11, 2026 at 14:55 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to a recent AVideo release that includes a fix removing the improper donationLink validation.
  • Disable the Allow Donation Link feature in the CustomizeUser settings to eliminate the injection vector.
  • Clear all existing donationLink values and restrict updates to only properly validated URLs; if immediate update is not possible, blank the field in the database.

Generated by OpenCVE AI on September 11, 2026 at 14:55 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 11 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 11 Sep 2026 11:30:00 +0000

Type Values Removed Values Added
Description WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a stored cross-site scripting vulnerability in the user 'donationLink' profile field. User::setDonationLink() (objects/user.php) stores the value and save() validates it only with filter_var(..., FILTER_VALIDATE_URL), which accepts strings such as http://evil.example/"onmouseover=alert(document.domain)//, while getDonationLink() applies only strip_tags() and does not encode double quotes. plugin/CustomizeUser/actionButton.php echoes the value unencoded into an <a href="..."> attribute, and that button is included from view/modeYoutubeBottom.php on the watch page when the CustomizeUser option allowDonationLink is enabled. An authenticated user who updates their own profile via objects/userUpdate.json.php can therefore break out of the href attribute and inject an event handler that executes JavaScript in the browser of any visitor—including an administrator—who views the attacker's videos and interacts with (for example, hovers over) the donation button. The issue was unfixed at the time of reporting.
Title AVideo Stored XSS via donationLink in watch page button
First Time appeared Wwbn
Wwbn avideo
Weaknesses CWE-79
CPEs cpe:2.3:a:wwbn:avideo:-:*:*:*:*:*:*:*
Vendors & Products Wwbn
Wwbn avideo
References
Metrics cvssV3_1

{'score': 8.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N'}

cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-11T12:26:39.480Z

Reserved: 2026-09-11T10:51:59.215Z

Link: CVE-2026-89253

cve-icon Vulnrichment

Updated: 2026-09-11T12:24:24.904Z

cve-icon NVD

Status : Deferred

Published: 2026-09-11T12:16:55.533

Modified: 2026-09-11T15:21:12.850

Link: CVE-2026-89253

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T17:15:06Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')