Impact
The vulnerability is a stored cross‑site scripting flaw in the donationLink field of the AVideo platform. The field validator uses FILTER_VALIDATE_URL, which such as http://evil.example/"onmouseover=alert(document.domain)//. When the user retrieves the field, strip_tags removes any tags but does not encode double quotes, and plugin/ an <a href="..."></a> attribute. An authenticated user can set a malicious link in their profile via the userUpdate.json.php endpoint, and the malformed link will later be rendered in the donation button on any video that the user uploads. When a viewer—including administrators—visits the video and interacts in the viewer’s browser. This flaw allows the attacker to run arbitrary scripts in the context of any user who views the video.
Affected Systems
The flaw resides in the AVideo platform released by WWBN. It affects any installation that contains the code present in the commit c3edcc274c389816d434acadac07ee78eaf330c1. No specific product version is listed, commit or later without a proper fix are vulnerable.
Risk and Exploitability
The CVSS score of 9.3 indicates a critical severity. The attack requires only authenticated access to the user’s own profile to store the malicious link. Once stored, all users who view that user’s videos and interact with the donation button are exposed to the injected script. EPSS data is not available and the vulnerability is not listed in CISA KEV, but the high CVSS, low exploitation barrier, and broad impact scope make the risk substantial in an environment where the feature is enabled.
OpenCVE Enrichment