External risk intelligence

WWBN AVideo Stored Cross-Site Scripting Via Trailer URL

CVE advisorySeverity: CRITICAL (CVSS 9.3)

CVE-2026-105089

AVideo is a web-based video sharing platform typically deployed as a public-facing web application. Since the vulnerability resides within the application's interface templates and is accessible via standard browser interactions, it is commonly exposed to the internet in normal deployment scenarios.

Cross-site Scripting

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A stored cross-site scripting vulnerability in WWBN AVideo allows authenticated users to inject malicious scripts via video trailer URLs. This vulnerability could enable attackers to execute arbitrary JavaScript in users' browsers by exploiting how the application renders trailer URLs in templates and playlists. The main concern is confirming relevance and exposure within your WWBN AVideo instances.

  • Malicious scripts can be injected via video trailers.
  • Affects WWBN AVideo, a video-sharing platform.
  • Confirm relevance and exposure to understand impact.

Attack Path

How an attacker could exploit the issue

An attacker can exploit this vulnerability by starting with upload permissions and then injecting malicious script into a video trailer URL. This script is then rendered in templates and playlists, allowing it to break out of its intended context and execute arbitrary JavaScript in other users' browsers.

  • Attacker needs upload permissions.
  • Malicious trailer URL injected.
  • Arbitrary JavaScript execution.

Live Threat

Current exploitation, exposure, and threat context

WWBN AVideo, when deployed with YouPHPFlix2 templates, could allow an authenticated user with upload permissions to inject script into video trailers. This script could execute in other users' browsers when viewing channel playlists or trailers, potentially impacting their browsing sessions.

  • Stored script in video trailers.
  • Script execution via malicious trailer URL.
  • Compromised user browser sessions.

Operational Fix

Recommended remediation, mitigation, and detection steps

The WWBN AVideo platform, which allows users to upload video content, is affected by a stored cross-site scripting vulnerability. This requires identifying where the platform is deployed, confirming its exposure and business criticality, and then assigning ownership for remediation. The first practical move is to locate all instances of AVideo, verify their reachability and importance, and then determine the accountable owner to plan the appropriate response.

  • Platform or application owners should lead.
  • Verify public-facing instances and their reachability.
  • Coordinate vendor updates or implement compensating controls.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is WWBN AVideo?

WWBN AVideo is an open-source, web-based video sharing and streaming platform. Users typically deploy it to host, manage, and distribute video content similar to private or niche video-hosting services. Because it supports features like channel playlists and custom template themes, it is frequently used by organizations to provide media-rich interfaces to their viewers.

How does this stored cross-site scripting vulnerability work?

This vulnerability is classified as CWE-79. It occurs because the application does not properly clean or 'escape' input provided in the video trailer URL field. When a user with upload access provides a malicious link, the system saves it to the database. Later, when other users view a playlist or template using that data, the browser interprets the injected code as a command rather than plain text, allowing it to execute arbitrary JavaScript.

Does any user on the platform trigger this bug?

No. A basic visitor or viewer cannot trigger this flaw. The exploit requires an account that already possesses specific 'upload' permissions. By design, the vulnerability is not triggered by simply browsing the site; it specifically requires the malicious URL to be saved within the system so that it subsequently executes when unsuspecting victims load the compromised video trailer or playlist page.

Why should I care about CVE-2026-105089?

According to Halo Surface Signal, AVideo is typically deployed as a public-facing web application. Since the vulnerability resides in the application's interface, any instance reachable over the internet is a potential target. If your organization uses AVideo to serve content to public users, they could be subjected to unauthorized script execution, which may lead to session hijacking or other browser-based attacks when they interact with your playlists.

What are the first steps to address this in my environment?

Begin by inventorying your infrastructure to locate all active WWBN AVideo instances. Once you have identified them, determine which are accessible to the internet versus those restricted to internal users. Coordinate with the application owners to assess the risk based on your specific deployment, and prepare to apply patches or updates from the vendor as they become available to neutralize the script injection path.

References