Sceawere

Vulnerability Detail

CVE-2026-105086UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

WWBN AVideo Stored XSS

Vulnerability Metadata

Severity
High
Score / CVSS
8.7
Creation Date
4h ago
Vendor
WWBN
Product
AVideo
Attack Type
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N
Attack Complexity
LOW

Narrative and Response

Description

WWBN AVideo 12.4 through 29.2.0 contains a stored cross-site scripting vulnerability that allows authenticated uploaders to inject HTML by submitting doubly-encoded entities in video titles. Because safeString() strips tags before decoding entities and runs twice via setTitle() and save(), attackers can store markup that executes in trending, gallery, embed, and playlist pages.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "8.7",
  "pubDate": "2026-10-04T16:16:30.183Z",
  "pubdate": "2026-10-04T16:16:30.183Z",
  "executiveSummary": "WWBN AVideo versions 12.4 through 29.2.0 are vulnerable to a stored cross-site scripting (XSS) vulnerability. This vulnerability resides in the application's video title processing logic, allowing authenticated users with upload privileges to inject arbitrary HTML and JavaScript into the platform.\nThe flaw stems from an improper sequence of input sanitization and entity decoding, specifically involving the safeString() function. By submitting doubly-encoded HTML entities within video titles, attackers can bypass security controls that are intended to strip malicious markup.\nSuccessful exploitation allows attackers to execute unauthorized JavaScript in the context of other users' sessions, including administrators, when they view affected pages such as the trending, gallery, embed, or playlist views. The primary risk involves session hijacking, unauthorized actions on behalf of the victim, and potential platform defacement. This vulnerability requires an authenticated user with video upload capabilities, representing a significant risk to the integrity and confidentiality of the AVideo environment.",
  "technicalDetails": "The root cause of this vulnerability is a flaw in the input validation and sanitization pipeline within the AVideo application, specifically concerning the handling of user-supplied video titles. The application utilizes a function named safeString() designed to strip potentially dangerous HTML tags; however, the architectural implementation of this function is flawed due to the order of operations in the data processing flow.\nThe application invokes safeString() twice: once during the setTitle() process and subsequently during the save() operation. Because safeString() performs tag stripping prior to decoding HTML entities, the use of doubly-encoded entities allows the payload to pass through the initial sanitization phase unscathed. When the data is processed a second time during the save operation, the decoding process effectively restores the malicious markup that the initial sanitization logic intended to remove.\nThe exploitation flow is as follows: An authenticated user with sufficient privileges to upload videos initiates a request containing a video title crafted with doubly-encoded HTML entities (e.g., &amp;lt;script&amp;gt;). The first pass of safeString() encounters the encoded string, which does not contain literal '<' or '>' characters, and therefore treats the input as safe. During the subsequent save() process, the double-decoding converts these entities into functional HTML tags that are then persisted to the database.\nOnce the malicious payload is successfully stored in the database, it is rendered on multiple pages throughout the application, including trending lists, galleries, embed viewers, and playlist interfaces. When a victim views these pages, the injected JavaScript executes within the victim's browser session. The context of this execution depends on the victim's privileges, but generally allows for the manipulation of the document object model (DOM), theft of session cookies, or the redirection of users to malicious external sites. The vulnerability is persistent, meaning the malicious payload remains active until it is manually removed from the database or the record is deleted. This flaw affects all AVideo versions from 12.4 through 29.2.0."
}
CVE-2026-105086: WWBN AVideo Stored XSS (HIGH Severity, CVSS: 8.7) | Sceawere