Impact
A stored cross‑site scripting flaw exists in the Bookmark plugin of AVideo. Chapter names entered by a video owner are inserted directly into the watch‑page HTML without HTML encoding or sanitization. Because the payload executes in the context of the site’s origin, any script injected into a bookmark name runs in the browser of every user who views the affected video. This can lead to session hijacking, credential theft, or the execution of arbitrary client‑side code.
Affected Systems
The vulnerability affects AVideo from WWBN, specifically the state of the repository at commit c3edcc274c389816d434acadac07ee78eaf330c1. No specific product version numbers are listed, so any deployment of AVideo that contains this commit is susceptible until patched.
Risk and Exploitability
The CVSS score of 9.3 indicates high severity, but the EPSS score is not provided. The vulnerability is not listed in the CISA KEV catalog, so no known public exploits are documented. The attack requires an authenticated video owner who can create or edit bookmark entries; once a malicious bookmark name is stored, any visitor to the video will execute the injected script. This stored‑XSS makes the exploit widely available to any user of the affected video, providing a broad surface for client‑side attacks.
OpenCVE Enrichment