<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>AVideo (12.4 Through 29.2.0) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/avideo-12.4-through-29.2.0/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Sun, 04 Oct 2026 16:54:10 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/avideo-12.4-through-29.2.0/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Stored Cross-Site Scripting in WWBN AVideo via Video Titles</title><link>https://feed.craftedsignal.io/briefs/2026-10-avideo-stored-xss/</link><pubDate>Sun, 04 Oct 2026 16:54:10 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-avideo-stored-xss/</guid><description>WWBN AVideo versions 12.4 through 29.2.0 are vulnerable to stored cross-site scripting (XSS) due to improper sanitization of doubly-encoded HTML entities in video titles, allowing authenticated attackers to execute arbitrary scripts in the context of gallery and playlist pages.</description><content:encoded><![CDATA[<p>WWBN AVideo, an open-source video platform, contains a stored cross-site scripting (XSS) vulnerability affecting versions 12.4 through 29.2.0 (CVE-2026-105086). The vulnerability arises from an improper input sanitization process involving the safeString() function. The application attempts to strip malicious HTML tags before decoding entities. However, due to a double-encoding flaw where entities are processed twice by the setTitle() and save() methods, an authenticated user can bypass these security checks. By submitting video titles containing doubly-encoded HTML entities, an attacker can store malicious JavaScript markup within the application database. This payload is subsequently rendered and executed when other users or administrators visit pages such as trending, gallery, embed, or playlist views. This vulnerability is significant as it allows for session hijacking, credential theft, or unauthorized actions performed on behalf of legitimate users who interact with the infected video content.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows authenticated attackers to inject and execute arbitrary JavaScript in the browsers of other users viewing the application. Potential consequences include the compromise of user sessions, theft of sensitive cookies, or unauthorized modification of application data. The vulnerability affects a broad range of AVideo versions (12.4 to 29.2.0), potentially impacting any organization hosting this video platform for internal or external media distribution.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Update WWBN AVideo to a version beyond 29.2.0 that includes the security patch for CVE-2026-105086.</li>
<li>Until patching is possible, implement strict input validation on the application's video metadata upload API to block doubly-encoded entities.</li>
<li>Audit application logs for suspicious activity on the video upload and metadata management endpoints.</li>
<li>Monitor for unexpected requests to the trending, gallery, or playlist pages that contain script-related characters.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category></item></channel></rss>