Junglewise Threat Intelligence

CVE-2026-85159: WWBN AVideo reflected XSS in userLogin.php

CVE-2026-85159 · Severity: medium · CVSS 5.4 · Published 2026-09-03

Technologies: WWBN AVideo. Vendors: WWBN.

Executive brief

AVideo is a video streaming and management platform. The login page contains a reflected cross-site scripting vulnerability in the cancelUri parameter that allows unauthenticated attackers to inject malicious JavaScript. When a user clicks the Cancel button on the login page, the injected script executes in their browser, potentially compromising their session or stealing sensitive information.

Technical details

The vulnerability is a reflected XSS (CWE-79) in userLogin.php where the cancelUri parameter is echoed into an href attribute without HTML encoding. The isSafeRedirectURL() function checks protocol and domain but does not validate or escape HTML special characters. An attacker can bypass this check using a relative URL like /" onmouseover="alert(1) which passes the protocol check but breaks out of the href attribute when rendered. The attack requires no authentication and no privileges, but does require user interaction (mouseover the Cancel button). The fix is to apply htmlspecialchars() with ENT_QUOTES flag before output.

Affected products

  • WWBN AVideo through commit c91b5975d

Timeline

  • 2026-08-19: disclosed: GitHub Security Advisory GHSA-mw3g-2292-vw4c published
  • 2026-09-03: advisory: CVE-2026-85159 published to NVD

References

Related threats