Description
AVideo fails to sanitize the phone field during user registration, allowing unauthenticated attackers to inject malicious JavaScript that persists in the database. When administrators visit the users management page, the unsanitized phone value is rendered via innerHTML, executing the injected script in the admin's browser session.
Published: 2026-08-11
Score: 5.1 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 11 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 11 Aug 2026 12:30:00 +0000

Type Values Removed Values Added
Description AVideo fails to sanitize the phone field during user registration, allowing unauthenticated attackers to inject malicious JavaScript that persists in the database. When administrators visit the users management page, the unsanitized phone value is rendered via innerHTML, executing the injected script in the admin's browser session.
Title AVideo Stored Cross-Site Scripting via Unauthenticated Registration
First Time appeared Wwbn
Wwbn avideo
Weaknesses CWE-79
CPEs cpe:2.3:a:wwbn:avideo:14.2:*:*:*:*:*:*:*
cpe:2.3:a:wwbn:avideo:14.3.1:*:*:*:*:*:*:*
cpe:2.3:a:wwbn:avideo:14.3:*:*:*:*:*:*:*
cpe:2.3:a:wwbn:avideo:14.4:*:*:*:*:*:*:*
cpe:2.3:a:wwbn:avideo:18.0:*:*:*:*:*:*:*
cpe:2.3:a:wwbn:avideo:21.0:*:*:*:*:*:*:*
cpe:2.3:a:wwbn:avideo:22.0:*:*:*:*:*:*:*
cpe:2.3:a:wwbn:avideo:24.0:*:*:*:*:*:*:*
cpe:2.3:a:wwbn:avideo:25.0:*:*:*:*:*:*:*
cpe:2.3:a:wwbn:avideo:26.0:*:*:*:*:*:*:*
cpe:2.3:a:wwbn:avideo:29.0:*:*:*:*:*:*:*
Vendors & Products Wwbn
Wwbn avideo
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N'}

cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-08-11T17:59:50.727Z

Reserved: 2026-08-10T13:53:42.482Z

Link: CVE-2026-72747

cve-icon Vulnrichment

Updated: 2026-08-11T17:59:20.769Z

cve-icon NVD

Status : Received

Published: 2026-08-11T13:19:05.663

Modified: 2026-08-11T18:18:24.060

Link: CVE-2026-72747

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses