Description
AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a stored cross-site scripting vulnerability in the LoginControl plugin that fails to HTML-encode PGP public keys echoed into a textarea element. An authenticated attacker can inject malicious JavaScript by submitting a crafted public key, which executes in an administrator's session when viewing the user's profile tab.
Published: 2026-09-11
Score: 9.3 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Stored Cross‑Site Scripting
Action: Patch Immediately
AI Analysis

Impact

The LoginControl plugin in AVideo has a stored cross‑site scripting flaw where PGP encoding. An attacker who is authenticated can upload a crafted public key, causing injected the profile tab. The attack could lead to session hijacking, credential theft, or further malicious actions performed with the administrator’s privileges.

Affected Systems

The flaw affects the WWBN AVideo platform. Affected versions include any release that incorporates commit c3edcc274c389816d434acadac07ee78eaf330c1 or later before a patch is applied. There is no vendor‑specified version range in the advisory, so all recent installations are potentially vulnerable.

Risk and Exploitability

The CVSS score of 9.3 indicates high severity. EPSS data is not available, but the lack of KEV listing suggests no known widespread exploitation yet, yet the high CVSS indicates a serious vulnerability. The likely attack vector is via the web interface, requiring an authenticated user to upload a malicious public key. When an administrator later accesses the user profile, the stored script runs in that administrator’s session, potentially enabling unauthorized actions.

Generated by OpenCVE AI on September 11, 2026 at 14:23 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the LoginControl pluginE fix or remove the public key upload functionality from the plugin.
  • Encode PGP public keys before rendering them in HTML, or apply strict server‑side input validation to block non‑textual content.
  • Restrict the upload of public keys to users with the highest level of privilege, and audit or log such uploads for anomalous activity.

Generated by OpenCVE AI on September 11, 2026 at 14:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 11 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 11 Sep 2026 11:30:00 +0000

Type Values Removed Values Added
Description AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a stored cross-site scripting vulnerability in the LoginControl plugin that fails to HTML-encode PGP public keys echoed into a textarea element. An authenticated attacker can inject malicious JavaScript by submitting a crafted public key, which executes in an administrator's session when viewing the user's profile tab.
Title AVideo LoginControl Stored XSS via PGP Public Key
First Time appeared Wwbn
Wwbn avideo
Weaknesses CWE-79
CPEs cpe:2.3:a:wwbn:avideo:-:*:*:*:*:*:*:*
Vendors & Products Wwbn
Wwbn avideo
References
Metrics cvssV3_1

{'score': 8.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N'}

cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-11T14:04:01.548Z

Reserved: 2026-09-11T10:51:59.215Z

Link: CVE-2026-89255

cve-icon Vulnrichment

Updated: 2026-09-11T14:03:55.826Z

cve-icon NVD

Status : Deferred

Published: 2026-09-11T12:16:55.850

Modified: 2026-09-11T15:21:12.850

Link: CVE-2026-89255

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T16:45:14Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')