ZeroHour

CVE-2026-88866

niche

Stored XSS in WWBN AVideo LoginControl Plugin

CVSS 4.0
9.3 critical
EPSS
Published
()
Modified
AI analysis

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a stored cross-site scripting flaw in its LoginControl plugin, which saves the HTTP User-Agent header into login history without encoding it. Any authenticated user can trigger the flaw by logging in with a crafted User-Agent string, which gets stored without sanitization. When an administrator views the Login History page, the injected script executes in the administrator's browser within the admin session, allowing the attacker to perform actions or steal data as that admin. All AVideo deployments running the affected code with the LoginControl plugin active and with accounts able to authenticate are exposed. There is no evidence of in-the-wild exploitation, and no public proof-of-concept is known.

What to do: Update AVideo to a build newer than commit c3edcc274c389816d434acadac07ee78eaf330c1 when a patched release becomes available, or temporarily disable the LoginControl plugin as a mitigation. Restrict which accounts can authenticate, have administrators defer reviewing the Login History page, and audit stored login-history User-Agent entries for unexpected injected content.

Affected
WWBN AVideo (LoginControl plugin)through commit c3edcc274c389816d434acadac07ee78eaf330c1
Estimated exposure
nichelikely low thousands of self-hosted instances or fewer — AVideo is a niche self-hosted open-source video platform with no public active-install or internet-exposure counts, so this order-of-magnitude estimate reflects its limited deployment base rather than a measured figure.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a stored cross-site scripting vulnerability in the LoginControl plugin that fails to encode the User-Agent header before storing it in login history. Attackers with any valid login account can inject malicious scripts in the User-Agent header that execute in administrator browsers when viewing the Login History page, allowing script execution within the administrator session.

Weakness
CWE-79
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.