Reflected Cross-Site Scripting Vulnerability in WWBN AVideo
CVE-2026-89240

5.3MEDIUM

Key Information:

Vendor

Wwbn

Status
Vendor
CVE Published:
11 September 2026

What is CVE-2026-89240?

A reflected cross-site scripting vulnerability exists in WWBN AVideo through a specific code commit, where the unauthenticated GET parameter 'u' is interpolated into an '' tag's src attribute without proper URL or HTML encoding. This flaw enables remote attackers to create malicious links that close the src attribute and insert additional JavaScript code via an onerror handler. Users who open such links risk executing arbitrary JavaScript code, jeopardizing the security of the site and its users, including administrators. There was no patched version available at the time of the advisory.

Affected Version(s)

AVideo 0

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

santhreal
.