{"id":"GHSA-c8h8-vq34-9fw2","summary":"WWBN AVideo: Stored XSS via unescaped Gallery category description","details":"### Summary\n\n  AVideo stores category descriptions from user input and later renders `category_description` as raw HTML in the Gallery view. A user who can create or edit\ncategories can store JavaScript in a category description, which executes when another user views the affected Gallery/category page.\n\n  This is a stored XSS in the category `description` field, separate from previously fixed XSS issues in video titles or comments.\n\n  ### Details\n\n  Source:\n\n  `objects/categoryAddNew.json.php`\n\n  ```php\n  $objCat-\u003esetDescription($_POST['description']);\n\n  Storage setter:\n\n  objects/category.php\n\n  public function setDescription($description)\n  {\n      $this-\u003edescription = $description;\n  }\n```\n  Sink:\n\n  `plugin/Gallery/view/mainAreaCategory.php`\n```\n  \u003cdiv id=\"categoryDescription\u003c?php echo $duid; ?\u003e\" style=\"display: none;\"\u003e\u003c?php echo $videos[0]['category_description']; ?\u003e\u003c/div\u003e\n```\n  The value is rendered without `htmlspecialchars()`, `htmlentities()`, `HTMLPurifier`, or equivalent output encoding.\n\n  ### PoC\n\n  Prerequisites:\n\n  - AVideo current master / v29.0\n  - User account with permission to create or edit categories\n  - Gallery plugin/view enabled\n  - At least one video assigned to the affected category\n\n  Steps:\n\n  1. Log in as a user who can create or edit categories.\n  2. Create or edit a category.\n  3. Set the category description to:\n```\n  \u003cimg src=x onerror=alert(document.domain)\u003e\n```\n  4. Save the category.\n  5. Assign at least one video to that category.\n  6. Open the Gallery/category page that renders the category section.\n  7. The payload is inserted into the page as raw HTML and JavaScript executes.\n\n  ### Impact\n\n  An attacker with category edit permission can execute JavaScript in the browser of users or administrators who view the affected Gallery/category page. This can\n  be used to perform actions as the victim, steal same-origin data accessible to JavaScript, or abuse administrative UI actions if an administrator views the\n  malicious category.\n\n### Recommended fix\n\n- Sanitize category descriptions on input with the same HTML policy used for video descriptions, or store plain text only.\n- Encode on output:\n\n```php\necho htmlspecialchars($videos[0]['category_description'], ENT_QUOTES, 'UTF-8');\n```\n\n- If limited HTML is intended, run the description through HTMLPurifier before storage or before render.\n- Add regression tests for category description rendering in Gallery views.","aliases":["CVE-2026-47694"],"modified":"2026-09-10T03:51:08.419797686Z","published":"2026-06-04T18:46:31Z","database_specific":{"github_reviewed_at":"2026-06-04T18:46:31Z","nvd_published_at":"2026-05-29T14:16:31Z","cwe_ids":["CWE-79"],"severity":"MODERATE","github_reviewed":true},"references":[{"type":"WEB","url":"https://github.com/WWBN/AVideo/security/advisories/GHSA-c8h8-vq34-9fw2"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-47694"},{"type":"WEB","url":"https://github.com/WWBN/AVideo/commit/6a6ff1f5bff1904f91f612db9f0da083295392b1"},{"type":"PACKAGE","url":"https://github.com/WWBN/AVideo"}],"affected":[{"package":{"name":"WWBN/AVideo","ecosystem":"Packagist","purl":"pkg:composer/WWBN/AVideo"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"29.0"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-c8h8-vq34-9fw2/GHSA-c8h8-vq34-9fw2.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"}]}