Executive brief
WWBN AVideo is a video streaming platform that includes an optional advertising server plugin. The AD_Server plugin contains an XML injection flaw in its VMAP (Video Multiple Ad Playlist) handler that allows unauthenticated attackers to inject malicious ad breaks and URLs. An attacker can trick users into opening a crafted video link that injects fake advertisements and causes the player to make requests to attacker-controlled servers, enabling ad fraud and tracking of viewing sessions.
Technical details
The vulnerability is an XML injection (CWE-91) in plugin/AD_Server/VMAP.php, which processes base64- and JSON-decoded values from the $_REQUEST['vmaps'] parameter without proper output encoding. The timeOffset and idTag fields are written directly into XML attributes without using htmlspecialchars() or equivalent escaping. The vulnerability is reachable without authentication when the AD_Server plugin is enabled. An attacker crafts a malicious vmaps payload (containing a non-empty VAST.campaing entry) and induces a user to visit a video page or VMAP URL with the payload. This injects arbitrary <vmap:AdBreak> and <vmap:AdTagURI>/<vmap:AdSource> nodes into the generated XML, which the video player then requests via its IMA ad integration, resulting in ad injection and cross-origin requests from the victim's session. The issue remained unfixed at the time of public disclosure.
Affected products
- WWBN AVideo commit c3edcc274c389816d434acadac07ee78eaf330c1 and earlier
Timeline
- 2026-08-27: disclosed: GitHub Security Advisory GHSA-whh8-w65x-9fvx published
- 2026-09-11: advisory: NVD and VulnCheck advisory published as CVE-2026-89247