AVideo fails to sanitize the phone field during user registration, allowing unauthenticated attackers to inject malicious JavaScript that persists in the database. When administrators visit the users management page, the unsanitized phone value is rendered via innerHTML, executing the injected script in the admin's browser session.
Metrics
Affected Vendors & Products
References
History
Tue, 11 Aug 2026 12:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | AVideo fails to sanitize the phone field during user registration, allowing unauthenticated attackers to inject malicious JavaScript that persists in the database. When administrators visit the users management page, the unsanitized phone value is rendered via innerHTML, executing the injected script in the admin's browser session. | |
| Title | AVideo Stored Cross-Site Scripting via Unauthenticated Registration | |
| First Time appeared |
Wwbn
Wwbn avideo |
|
| Weaknesses | CWE-79 | |
| CPEs | cpe:2.3:a:wwbn:avideo:14.2:*:*:*:*:*:*:* cpe:2.3:a:wwbn:avideo:14.3.1:*:*:*:*:*:*:* cpe:2.3:a:wwbn:avideo:14.3:*:*:*:*:*:*:* cpe:2.3:a:wwbn:avideo:14.4:*:*:*:*:*:*:* cpe:2.3:a:wwbn:avideo:18.0:*:*:*:*:*:*:* cpe:2.3:a:wwbn:avideo:21.0:*:*:*:*:*:*:* cpe:2.3:a:wwbn:avideo:22.0:*:*:*:*:*:*:* cpe:2.3:a:wwbn:avideo:24.0:*:*:*:*:*:*:* cpe:2.3:a:wwbn:avideo:25.0:*:*:*:*:*:*:* cpe:2.3:a:wwbn:avideo:26.0:*:*:*:*:*:*:* cpe:2.3:a:wwbn:avideo:29.0:*:*:*:*:*:*:* |
|
| Vendors & Products |
Wwbn
Wwbn avideo |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-08-11T12:17:01.441Z
Reserved: 2026-08-10T13:53:42.482Z
Link: CVE-2026-72747
No data.
Status : Received
Published: 2026-08-11T13:19:05.663
Modified: 2026-08-11T13:19:05.663
Link: CVE-2026-72747
No data.
OpenCVE Enrichment
No data.