---
id: CVE-2026-89241
title: WWBN AVideo Reflected XSS via confirmLivePassword.php
summary: >-
  WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a
  reflected cross-site scripting vulnerability in confirmLivePassword.php that
  copies REQUEST_URI into a form action attribute without encoding. Attackers
  can c…
severity: medium
cvss: 6.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'
cvssSource: cna
cwe:
  - CWE-79
vendor: WWBN
product: AVideo
affected:
  - AVideo <= c3edcc274c389816d434acadac07ee78eaf330c1
ssvc:
  exploitation: poc
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-11T19:19:32.984619Z'
exploitAvailable: true
published: '2026-09-11'
updated: '2026-09-11'
sourceUpdated: '2026-09-11T19:19:40.565Z'
source: CVEORG
sourceUrl: 'https://www.cve.org/CVERecord?id=CVE-2026-89241'
references:
  - url: 'https://github.com/WWBN/AVideo/security/advisories/GHSA-fp9p-hrc9-8rr7'
    label: GitHub Security Advisory (GHSA-fp9p-hrc9-8rr7)
  - url: >-
      https://www.vulncheck.com/advisories/wwbn-avideo-reflected-xss-via-confirmlivepassword-php-2
    label: 'VulnCheck Advisory: WWBN AVideo Reflected XSS via confirmLivePassword.php'
tags:
  - cve.org
  - exploit-available
epss: 0.00197
epssPercentile: 0.09778
ingestedAt: '2026-09-14T00:35:28.534Z'
---

## Overview

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a reflected cross-site scripting vulnerability in confirmLivePassword.php that copies REQUEST_URI into a form action attribute without encoding. Attackers can craft a malicious URL with a quote character to break out of the action attribute and inject event handlers that execute in the victim's browser within the site origin.

## Affected

- `AVideo <= c3edcc274c389816d434acadac07ee78eaf330c1`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
