CVE-2026-89243: WWBN AVideo Stored XSS via UserGroups setGroup_name
WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a stored cross-site scripting vulnerability in UserGroups::setGroupname() that fails to sanitize groupname input. Administrators with canAdminUserGroups permission can inject malicious HTML and JavaScript that executes in the browser when other administrators access the user manager interface.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue, and who is exposed to the payload?
An attacker needs administrator-level access with the canAdminUserGroups permission to submit a malicious group name. The stored payload executes when other administrators open the user manager interface.
Does exploitation require user interaction?
Yes. A target administrator must access the user manager interface after the malicious group name has been stored.
How can I check whether the instance may already be affected?
Review user group names and related administrative changes for unexpected HTML or JavaScript content. Also identify accounts with canAdminUserGroups permission, since those accounts can create the malicious input.