Impact
A stored cross‑site scripting vulnerability exists in the CustomizeUser plugin of AVideo. The flaw is triggered when the field_name parameter is submitted to the add.json.php endpoint and the value is stored without sanitization. When the stored value is later rendered in extra info pages or profile forms through the typeToHTML function, the embedded script executes in the browser context of any user who views the affected page. This can lead to malicious content injection, session hijacking, or def input validation flaw, identified as CWE‑79.
Affected Systems
The affected product is AVideo from WWBN. All installations that run any version of AVideo with the default CustomizeUser plugin configuration are susceptible until the patch or mitigation is applied. No specific version boundary has been cited by the CNA.
Risk and Exploitability
The CVSS score of 9.3 indicates a high exploitable risk. The EPSS score is not currently available, and the vulnerability is not listed in CISA’s KEV catalog, suggesting there is no confirmed exploitation in the wild yet. The primary attack surface is submitting a value to add.json.php; once stored, the malicious code is delivered to all users who view the edited profile access can inject arbitrary scripts that execute with the same privileges as the page viewer.
OpenCVE Enrichment