PT-2026-27186 · Avideo · Avideo

Restriction

·

Publicado

2026-03-23

·

Atualizado

2026-03-25

·

CVE-2026-33683

CVSS v3.1

5.4

Média

VetorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions AVideo versions up to and including 26.0
Description A flaw exists in the order of operations during sanitization of the user profile "about" field. This allows any registered user to inject arbitrary JavaScript that executes when other users visit their channel page. The xss esc() function entity-encodes input before the strip specific tags() function can identify and remove dangerous HTML tags. Subsequently, the html entity decode() function reverses the encoding on output, restoring the original malicious HTML.
Recommendations Update to a version after 26.0.

Exploit

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-33683
GHSA-GHX5-7JJG-Q2J7

Produtos afetados

Avideo