Executive brief
AVideo, an open-source video platform, contains a vulnerability that allows users with upload permissions to send deceptive emails to thousands of subscribers. These emails appear to be official communications from the platform, complete with the site's logo and official contact address. Attackers can use this to distribute phishing links or tracking pixels, potentially leading to account takeovers or the theft of user information.
Technical details
A vulnerability in `objects/notifySubscribers.json.php` allows authenticated users with the `canUpload` permission to perform HTML injection. The `message` POST parameter is passed to `sendSiteEmail()` and subsequently `PHPMailer::msgHTML()` without sanitization or escaping. An attacker can broadcast arbitrary HTML—including phishing links and tracking pixels—to up to 10,000 subscribers per request. The emails are sent from the platform's configured contact address and use the official site template, making them appear legitimate. Additionally, a logic flaw in `createEmailMessageFromTemplate` allows attackers to bypass the site template entirely by including an `<html>` tag in their payload.
Affected products
- WWBN AVideo <= 29.0
Timeline
- 2026-04-25: disclosed
- 2026-05-05: advisory