Stored Cross-Site Scripting Vulnerability in AVideo by WWBN
CVE-2026-88866
9.3CRITICAL
What is CVE-2026-88866?
The AVideo platform, specifically its LoginControl plugin, is affected by a stored cross-site scripting vulnerability. This issue arises from the plugin's failure to properly encode the User-Agent header before it is stored in the login history. This vulnerability allows attackers, using valid login credentials, to inject malicious scripts. When administrators view the Login History page, these scripts execute in their browsers, potentially compromising their sessions and opening pathways for further attacks. It's crucial for users of AVideo to address this vulnerability to protect against unauthorized access and manipulation.
Affected Version(s)
AVideo 0
