Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Alto CVE-2026-89253 Multiple Vendors

Vulnerabilidad XSS almacenado alta en WWBN AVideo (CVE-2026-89253)

Vulnerabilidad · Publicado 11/09/2026

8.7
CVSS 3.x
04 Medio7 Alto9 Crítico10
Severidad: Alto
Resumen ejecutivo

WWBN AVideo contiene una vulnerabilidad de cross-site scripting (XSS) almacenado en el campo de perfil 'donationLink' que permite a usuarios autenticados inyectar código malicioso. La validación insuficiente en la función setDonationLink() acepta URLs malformadas con cargas de script. Afecta principalmente a plataformas de streaming y educación en línea que utilizan este software en servidores locales o en la nube en LATAM.

Análisis asistido por IA, contexto LATAM revisado por el equipo 2MCI.

Descripción técnica

Descripción técnica

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a stored cross-site scripting vulnerability in the user 'donationLink' profile field. User::setDonationLink() (objects/user.php) stores the value and save() validates it only with filter_var(..., FILTER_VALIDATE_URL), which accepts strings such as http://evil.example/"onmouseover=alert(document.domain)//, while getDonationLink() applies only strip_tags() and does not encode double quotes. plugin/CustomizeUser/actionButton.php echoes the value unencoded into an <a href="..."> attribute, and that button is included from view/modeYoutubeBottom.php on the watch page when the CustomizeUser option allowDonationLink is enabled. An authenticated user who updates their own profile via objects/userUpdate.json.php can therefore break out of the href attribute and inject an event handler that executes JavaScript in the browser of any visitor—including an administrator—who views the attacker's videos and interacts with (for example, hovers over) the donation button. The issue was unfixed at the time of reporting.

Puntuación CVSS

Score: 8.7/10 — Severidad: HIGH — Estado NIST: Received

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N

Debilidades (CWE)

CWE-79

Fuente oficial

Publicado en NIST NVD.

¿Qué hacer?
  • Inventariar instancias de WWBN AVideo en producción
  • Actualizar a commits posteriores a c3edcc274c389816d434acadac07ee78eaf330c1
  • Implementar validación estricta de URLs en campos de perfil
  • Revisar logs de cambios en perfiles de usuario para detectar explotación
  • Aplicar restricciones de Content Security Policy (CSP)
  • Consultar NIST NVD para parches oficiales del desarrollador
Esta alerta fue generada automáticamente a partir del NVD del NIST.