AVideo fails to sanitize the phone field during user registration, allowing unauthenticated attackers to inject malicious JavaScript that persists in the database. When administrators visit the users management page, the unsanitized phone value is rendered via innerHTML, executing the injected script in the admin's browser session.
Metrics
Affected Vendors & Products
References
History
Tue, 11 Aug 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 11 Aug 2026 12:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | AVideo fails to sanitize the phone field during user registration, allowing unauthenticated attackers to inject malicious JavaScript that persists in the database. When administrators visit the users management page, the unsanitized phone value is rendered via innerHTML, executing the injected script in the admin's browser session. | |
| Title | AVideo Stored Cross-Site Scripting via Unauthenticated Registration | |
| First Time appeared |
Wwbn
Wwbn avideo |
|
| Weaknesses | CWE-79 | |
| CPEs | cpe:2.3:a:wwbn:avideo:14.2:*:*:*:*:*:*:* cpe:2.3:a:wwbn:avideo:14.3.1:*:*:*:*:*:*:* cpe:2.3:a:wwbn:avideo:14.3:*:*:*:*:*:*:* cpe:2.3:a:wwbn:avideo:14.4:*:*:*:*:*:*:* cpe:2.3:a:wwbn:avideo:18.0:*:*:*:*:*:*:* cpe:2.3:a:wwbn:avideo:21.0:*:*:*:*:*:*:* cpe:2.3:a:wwbn:avideo:22.0:*:*:*:*:*:*:* cpe:2.3:a:wwbn:avideo:24.0:*:*:*:*:*:*:* cpe:2.3:a:wwbn:avideo:25.0:*:*:*:*:*:*:* cpe:2.3:a:wwbn:avideo:26.0:*:*:*:*:*:*:* cpe:2.3:a:wwbn:avideo:29.0:*:*:*:*:*:*:* |
|
| Vendors & Products |
Wwbn
Wwbn avideo |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-08-11T17:59:50.727Z
Reserved: 2026-08-10T13:53:42.482Z
Link: CVE-2026-72747
Updated: 2026-08-11T17:59:20.769Z
Status : Received
Published: 2026-08-11T13:19:05.663
Modified: 2026-08-11T18:18:24.060
Link: CVE-2026-72747
No data.
OpenCVE Enrichment
Updated: 2026-08-12T00:15:12Z