PT-2026-29360 · Unknown+1 · Jquery Toast Plugin+1
Adrgs
·
Published
2026-03-31
·
Updated
2026-04-01
·
CVE-2026-34716
CVSS v3.1
6.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
AVideo versions 26.0 and prior
Description
The AVideo YPTSocket plugin's caller feature in versions 26.0 and prior renders incoming call notifications using the jQuery Toast Plugin, passing the caller's display name directly as the heading parameter. The toast plugin constructs the heading as raw HTML and inserts it into the DOM via jQuery's .html() method, which parses and executes any embedded HTML or script content. An attacker can set their display name to a cross-site scripting (XSS) payload and trigger code execution on any online user's browser simply by initiating a call. No victim interaction is required beyond being connected to the WebSocket.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Avideo
Jquery Toast Plugin