Junglewise Threat Intelligence

CVE-2026-82646: WWBN AVideo unauthenticated reflected XSS in url2Embed.json.php

CVE-2026-82646 · Severity: medium · CVSS 6.1 · Published 2026-08-30

Technologies: WWBN AVideo. Vendors: WWBN.

Executive brief

WWBN AVideo is an open-source video hosting and streaming platform. An unauthenticated attacker can inject malicious JavaScript code through a specially crafted URL, which the platform encrypts and returns as an innocent-looking share link on the site's own domain. When a victim clicks this link, the attacker's script runs in their browser session, allowing theft of session cookies and CSRF tokens.

Technical details

This is a reflected cross-site scripting (XSS) vulnerability in the url2Embed.json.php endpoint. The root cause is insufficient input validation: the isValidURL() function uses only PHP's filter_var() with FILTER_VALIDATE_URL, which accepts HTML metacharacters (quotes, angle brackets) in the URL path and query string. The endpoint encrypts this malicious URL into an evideo payload and returns it as a base64-encoded blob. When the encrypted link is accessed, view/videoEmbeded.php and view/modeYoutube.php decrypt the payload and print the videoLink parameter unescaped in at least 10 locations (meta tags, iframe src, anchor href, onclick handlers, canonical link). The attack requires only two unauthenticated requests and no user account. An attacker can craft a URL like https://x.com/a"><script>alert(1)</script>, mint it into an encrypted blob that appears as a legitimate share link from the site itself, and distribute it to victims. No patch is currently available.

Affected products

  • WWBN AVideo current (e01e41ecc) and earlier

Timeline

  • 2026-08-14: disclosed
  • 2026-08-30: advisory

References

Related threats