Description
AVideo through 29.0 (current revision e01e41ecc) contains a stored cross-site scripting vulnerability. The unauthenticated view-counter endpoint objects/videoAddViewCount.json.php reaches VideoStatistic::save(), which writes the caller's User-Agent (via getUserAgentInfo(), which returns unrecognized agent strings verbatim) directly into the `app` column of the videos_statistics table without invoking the sanitizing setter setApp(); normalizeApp() only truncates the value to 45 characters. The video owner's and administrator's statistics page (view/videoViewsInfo.php) renders this field in a DataTables 1.12.1 column with an unescaped renderer, and DataTables assigns cell content using innerHTML, so attacker-supplied HTML is parsed and executed in the privileged user's authenticated session when the statistics page is viewed. No patched version was available at the time of the advisory.
Published: 2026-09-16
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Stored cross‑site scripting that can execute arbitrary JavaScript within an authenticated administrator's session
Action: Patch Now
AI Analysis

Impact

A video‑analytics application retains the exact User‑Agent string sent by a client in a database field without sanitization. The string is later rendered inside an unescaped DataTables cell, allowing an attacker’s malicious HTML or script to execute in the browser of anyone who views the statistics page. This delivers the attacker’s script to a privileged user’s authenticated session, potentially exposing session cookies, personal data, or enabling further privilege escalation. The weakness is a classic stored cross‑site scripting flaw (CWE‑79).

Affected Systems

The vulnerability exists in AVideo version 29.0 and earlier (revision e01e41ecc). No patch has been released as of the advisory; the issue is present in all installations of the affected releases that expose the unprotected view‑counter endpoint.

Risk and Exploitability

The vulnerability carries a CVSS score of 5.3, indicating moderate severity, while its EPSS score is less than 1 %, implying a low probability of exploitation at the present time. It is not listed in the CISA KEV catalog. Attackers can inject the malicious payload by simply sending a crafted User‑Agent header to the unauthenticated view‑counter endpoint; the stored data is later delivered to a logged‑in administrator when the statistics page is rendered. The threat is limited to browsers running the application and requires no special privileges beyond matching a known endpoint. The high‑impact nature of executing code in an authenticated context, however, warrants prompt remediation once a patch becomes available.

Generated by OpenCVE AI on September 18, 2026 at 05:23 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Restrict access to the view‑counter endpoint to authenticated administrators only, preventing unauthenticated clients from injecting data
  • Sanitize or escape the User‑Agent string before storing it in the database, or apply proper HTML escaping when rendering the app column in DataTables
  • Monitor for updates to AVideo and apply the next available patch immediately once the vendor releases a fix

Generated by OpenCVE AI on September 18, 2026 at 05:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
Description AVideo through 29.0 (current revision e01e41ecc) contains a stored cross-site scripting vulnerability. The unauthenticated view-counter endpoint objects/videoAddViewCount.json.php reaches VideoStatistic::save(), which writes the caller's User-Agent (via getUserAgentInfo(), which returns unrecognized agent strings verbatim) directly into the `app` column of the videos_statistics table without invoking the sanitizing setter setApp(); normalizeApp() only truncates the value to 45 characters. The video owner's and administrator's statistics page (view/videoViewsInfo.php) renders this field in a DataTables 1.12.1 column with an unescaped renderer, and DataTables assigns cell content using innerHTML, so attacker-supplied HTML is parsed and executed in the privileged user's authenticated session when the statistics page is viewed. No patched version was available at the time of the advisory.
Title AVideo through 29.0 Stored Cross-Site Scripting via User-Agent Header
First Time appeared Wwbn
Wwbn avideo
Weaknesses CWE-79
CPEs cpe:2.3:a:wwbn:avideo:*:*:*:*:*:*:*:*
Vendors & Products Wwbn
Wwbn avideo
References
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-21T14:55:13.089Z

Reserved: 2026-09-16T13:47:20.117Z

Link: CVE-2026-92584

cve-icon Vulnrichment

Updated: 2026-09-21T14:54:46.108Z

cve-icon NVD

Status : Deferred

Published: 2026-09-16T22:18:28.890

Modified: 2026-09-22T20:43:58.793

Link: CVE-2026-92584

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T06:30:05Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')