Unauthenticated Reflected XSS in WWBN AVideo Product by WWBN
CVE-2026-82646
5.3MEDIUM
What is CVE-2026-82646?
The WWBN AVideo platform includes a vulnerability in the url2Embed.json.php endpoint that permits unauthenticated reflected cross-site scripting attacks. By manipulating URL inputs that include HTML metacharacters, attackers can forge encrypted evideo payloads containing unescaped markup. This enables them to create links that appear legitimate but execute malicious JavaScript in the context of the victim's session, potentially compromising cookies and CSRF tokens.
