Junglewise Threat Intelligence

CVE-2026-88869: AVideo AD_Server stored XSS in log.php label parameter

CVE-2026-88869 · Severity: critical · CVSS 9.3 · Published 2026-09-10

Technologies: WWBN AVideo. Vendors: WWBN.

Executive brief

AVideo is a video platform with an optional AD_Server plugin that tracks advertising campaigns. An unauthenticated attacker can inject malicious JavaScript code through an unprotected tracking endpoint, which is then executed when administrators view advertising reports. This allows an attacker to hijack administrator accounts and take full control of the video platform, including user management and site configuration.

Technical details

This is a stored cross-site scripting (XSS) vulnerability in the AD_Server plugin's log.php endpoint. The vulnerability occurs because user input from the `label` parameter is copied directly into the database without sanitization via xss_esc(). When administrators view the Ad Types report, this stored payload is rendered using jQuery's .html() method, which interprets and executes the injected HTML and JavaScript. No authentication is required to send the malicious request, only a same-origin Referer header (satisfied by normal browser behavior). The attacker's JavaScript runs in the administrator's browser session with full access to the site origin, enabling account takeover and site compromise. As of the advisory date, no patch was available.

Affected products

  • WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 with AD_Server plugin enabled

Timeline

  • 2026-08-26: disclosed: GitHub Security Advisory GHSA-h68w-3r38-wmm8 published
  • 2026-09-10: advisory: CVE-2026-88869 assigned and published

References

Related threats