CVE-2026-88866
nicheStored XSS in WWBN AVideo LoginControl Plugin
WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a stored cross-site scripting flaw in its LoginControl plugin, which saves the HTTP User-Agent header into login history without encoding it. Any authenticated user can trigger the flaw by logging in with a crafted User-Agent string, which gets stored without sanitization. When an administrator views the Login History page, the injected script executes in the administrator's browser within the admin session, allowing the attacker to perform actions or steal data as that admin. All AVideo deployments running the affected code with the LoginControl plugin active and with accounts able to authenticate are exposed. There is no evidence of in-the-wild exploitation, and no public proof-of-concept is known.
What to do: Update AVideo to a build newer than commit c3edcc274c389816d434acadac07ee78eaf330c1 when a patched release becomes available, or temporarily disable the LoginControl plugin as a mitigation. Restrict which accounts can authenticate, have administrators defer reviewing the Login History page, and audit stored login-history User-Agent entries for unexpected injected content.
| WWBN AVideo (LoginControl plugin) | through commit c3edcc274c389816d434acadac07ee78eaf330c1 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a stored cross-site scripting vulnerability in the LoginControl plugin that fails to encode the User-Agent header before storing it in login history. Attackers with any valid login account can inject malicious scripts in the User-Agent header that execute in administrator browsers when viewing the Login History page, allowing script execution within the administrator session.
- Weakness
- CWE-79
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.