Sceawere

Vulnerability Detail

CVE-2026-105089UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

WWBN AVideo Stored XSS

Vulnerability Metadata

Severity
High
Score / CVSS
8.7
Creation Date
1d ago
Vendor
WWBN
Product
AVideo
Attack Type
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N
Attack Complexity
LOW

Narrative and Response

Description

WWBN AVideo through 29.2.0 contains a stored cross-site scripting vulnerability that allows users with upload permission to inject script by setting a malicious video trailer1 URL. The value is rendered unescaped in YouPHPFlix2 templates and channel playlists, letting attackers break out of onclick strings or iframe src attributes to execute JavaScript in victims' browsers.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "8.7",
  "pubDate": "2026-10-04T16:16:30.330Z",
  "pubdate": "2026-10-04T16:16:30.330Z",
  "executiveSummary": "WWBN AVideo through version 29.2.0 is susceptible to a stored Cross-Site Scripting (XSS) vulnerability. The flaw resides in the handling of video trailer URLs within the YouPHPFlix2 templates and channel playlists.\nThis vulnerability allows authenticated users with upload privileges to inject arbitrary malicious scripts by manipulating the 'trailer1' URL field. When the application renders this data, it fails to perform adequate input sanitization or output encoding, leading to the execution of attacker-supplied JavaScript within the context of a victim's browser session.\nThe primary risk implication involves the unauthorized execution of code in the victim's browser, potentially leading to session hijacking, credential theft, or unauthorized actions performed on behalf of the user. Exploitation requires the attacker to possess at least the minimum privilege level necessary to upload videos. Because the malicious payload is stored within the application's database, it affects all users who interact with the compromised trailer content, facilitating wide-scale impact within the affected instances.",
  "technicalDetails": "The vulnerability is a classic stored XSS flaw resulting from improper output neutralization of user-controlled input. In WWBN AVideo, the 'trailer1' URL parameter is accepted via the upload or media configuration interface without sufficient validation or context-aware encoding. This input is subsequently stored directly in the backend database.\nThe root cause of the vulnerability is the application's reliance on unescaped rendering of this stored data within the YouPHPFlix2 template engine and channel playlist modules. When a victim accesses a page containing the malicious video metadata, the server reflects the unsanitized 'trailer1' value into the HTML document structure.\nExploitation is achieved by injecting a payload designed to break out of the intended HTML attribute context. For instance, if the application inserts the trailer URL into an 'onclick' event handler or an 'iframe' 'src' attribute, an attacker can craft a payload that closes the current attribute string and introduces new malicious event handlers or script tags. An attacker might use a payload structured like 'javascript:alert(1)//' or construct a sequence of characters that terminates the attribute (e.g., '\" onmouseover=\"[malicious_code]') to achieve code execution.\nThe attack flow follows these steps: 1) The authenticated attacker navigates to the video management or upload section. 2) The attacker submits a specially crafted string as the 'trailer1' URL for a video asset. 3) The application saves this malicious string to the database without filtering. 4) When a victim—which could be a regular user or an administrator—views the playlist or the YouPHPFlix2 interface, the server retrieves the malicious string from the database and injects it into the HTML response. 5) The victim's browser interprets the injected content as executable JavaScript rather than a valid URL string.\nThe scope of this vulnerability is significant, as it affects all versions of WWBN AVideo up to and including 29.2.0. Successful exploitation bypasses standard client-side protections and executes with the privileges of the victim. Post-exploitation, an attacker can steal session cookies, perform unauthorized actions in the administrative backend if the victim has such privileges, or redirect users to malicious external sites, thereby compromising the integrity and confidentiality of the AVideo platform and its users."
}
CVE-2026-105089: WWBN AVideo Stored XSS (HIGH Severity, CVSS: 8.7) | Sceawere