Junglewise Threat Intelligence

CVE-2026-85577: AVideo reflected XSS in userLogin.php

CVE-2026-85577 · Severity: medium · CVSS 5.4 · Published 2026-09-04

Technologies: WWBN AVideo. Vendors: WWBN.

Executive brief

AVideo is a self-hosted video streaming platform. The login page contains a reflected cross-site scripting (XSS) vulnerability in the error parameter that allows an unauthenticated attacker to inject malicious JavaScript. An attacker can craft a phishing URL to steal user credentials, redirect visitors to a malicious site, or perform other client-side attacks when users click the link.

Technical details

The vulnerability is a reflected XSS in userLogin.php at line 276, where the error parameter from $_GET is passed through addslashes() and echoed directly into a JavaScript script block without proper escaping. The addslashes() function only escapes single quotes, double quotes, backslashes, and NUL characters—it does not escape the </script> sequence. An unauthenticated attacker can close the script tag with </script> and inject arbitrary JavaScript payload. The attack requires user interaction (victim must visit or click the malicious URL). Exploitation allows arbitrary JavaScript execution in the victim's browser context on the login page, enabling credential phishing or DOM manipulation. The recommended fix is to use json_encode() or htmlspecialchars() with ENT_QUOTES and ENT_HTML5 flags before outputting the parameter in a script context.

Affected products

  • WWBN AVideo through commit c91b5975d

Timeline

  • 2026-08-20: disclosed: GitHub Security Advisory GHSA-v654-6qw8-pc33 published
  • 2026-09-04: advisory: CVE-2026-85577 published on NVD

References

Related threats