CVE-2026-88866 Details
Description
WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a stored cross-site scripting vulnerability in the LoginControl plugin that fails to encode the User-Agent header before storing it in login history. Attackers with any valid login account can inject malicious scripts in the User-Agent header that execute in administrator browsers when viewing the Login History page, allowing script execution within the administrator session.
A stored cross-site scripting vulnerability has been identified in the WWBN AVideo LoginControl plugin, affecting versions through commit c3edcc274c389816d434acadac07ee78eaf330c1. The vulnerability arises because the plugin does not properly encode the User-Agent header before saving it in the login history. This flaw allows attackers with valid login accounts to inject malicious scripts that are executed in the context of an administrator's browser when the Login History page is viewed. As a result, the injected script runs within the administrator session, potentially leading to unauthorized actions or data access.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 10, 2026CISA-ADP
Assessed Sep 15, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/WWBN/AVideo/security/advisories/GHSA-wg67-62q3-2m33 | CISA-ADP | AdvisoryExploitTechnical DescriptionVendor |
| https://github.com/WWBN/AVideo/security/advisories/GHSA-wg67-62q3-2m33 | [email protected] | AdvisoryExploitTechnical DescriptionVendor |
| https://www.vulncheck.com/advisories/wwbn-avideo-logincontrol-stored-xss-via-user-agent-header | [email protected] | Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-79 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| WWBN AVideo | <= c3edcc274c389816d434acadac07ee78eaf330c1 |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 15, 2026 | CVE Modified | CISA-ADP |
| Sep 10, 2026 | New CVE Received | [email protected] |
Volerion