Stored Cross-Site Scripting in WWBN AVideo UserGroups Management
CVE-2026-89243
9.2CRITICAL
What is CVE-2026-89243?
The vulnerability in WWBN AVideo allows administrators to input unsanitized data into the UserGroups::setGroup_name() function. This leads to the execution of malicious HTML and JavaScript when other administrators visit the user management interface, potentially compromising the security of the system. Proper input sanitization measures are essential to prevent such vulnerabilities.
Affected Version(s)
AVideo 0
