VYPR
Medium severity6.1NVD Advisory· Published Sep 11, 2026· Updated Sep 11, 2026

CVE-2026-89240

CVE-2026-89240

Description

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a reflected cross-site scripting vulnerability in plugin/Live/confirmLivePassword.php. The script interpolates the unauthenticated GET parameter u (which is not covered by $securityFilter) directly into an attribute without URL- or HTML-encoding. A remote attacker can craft a link containing a double-quote character in u (with a non-empty key parameter and no valid c parameter) to close the src attribute and inject an additional tag with an onerror handler, executing arbitrary JavaScript in the site's origin in the browser of any user, including an administrator, who opens the link. No patched version was available at the time of the advisory.

Affected products

2
  • WWBN/Avideoinferred2 versions
    <=commit c3edcc274c389816d434acadac07ee78eaf330c1+ 1 more
    • (no CPE)range: <=commit c3edcc274c389816d434acadac07ee78eaf330c1
    • (no CPE)range: <c3edcc274c389816d434acadac07ee78eaf330c1

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.