Skip to content
GHSA 6wfr C7fw 4xvw

GHSA 6wfr C7fw 4xvw

github.com • October 4, 2026

WWBN AVideo through 29.2.0 contains a stored cross-site scripting vulnerability that allows users with upload permission to inject JavaScript through the video trailer1 value. Attackers can store a trailer URL with quotes or angle brackets that bypasses FILTER_VALIDATE_URL and breaks out of onclick handlers or iframe src attributes in row_info.php, BigVideoButtons.php, BigVideo.php, and channelPlaylistItems.php. The script runs in the browser of any visitor, including administrators, who views the YouPHPFlix2 page or a channel playlist.

This is an incomplete fix of GHSA-v7vx-v9q9-qhw3 ("Stored XSS in video trailer1 field via HTML-entity bypass of isValidURL()").

The fix, 40b3267 (first released in v29.1.0), added htmlspecialchars() to the two templates the advisory names, plugin/CustomizeAdvanced/actionButton.php and actionButtonGallery.php. Four other templates render the same trailer1 value with no escaping, and, unlike those two, without the isValidURL() guard (only !empty() ). All four are unchanged in v29.1.0, v29.1.1, v29.2.0 and master :

plugin/YouPHPFlix2/view/row_info.php:163 onclick="flixFullScreen(' ', '');return false;"

plugin/YouPHPFlix2/view/BigVideoButtons.php:34 onclick="flixFullScreen(' ', '');return false;"

view/channelPlaylistItems.php:182 onclick="avideoModalIframe(' ');"

plugin/YouPHPFlix2/view/BigVideo.php:29 " ...>

Video::setTrailer1() (objects/video.php:4113) only checks FILTER_VALIDATE_URL , which accepts literal ' , " , and HTML entities in the path. So at these four sinks the entity trick from GHSA-v7vx is not even needed:

In the three onclick sinks, either ' or a literal ' closes the JavaScript string.

In BigVideo.php the value sits in a double-quoted src attribute, so a literal " closes the attribute and follows. That iframe is rendered on page load for the YouPHPFlix2 page (desktop), so no click is needed.

The onVideoSetTrailer1 plugin hook has no implementation, and nothing between the database row and these templates touches trailer1 .

Preconditions: an account with upload permission (to set trailer1 ), and a victim viewing a page that uses the YouPHPFlix2 theme or a channel playlist.

The scripts copy parseVideos() , isValidURL() and their helpers verbatim from objects/functions.php and reproduce what each template emits and what the browser hands to the JavaScript engine (the HTML-decoded attribute value). No server or database is needed.

Output at master @ 5e1701f :

JS after is the 40b3267 form ( htmlspecialchars ). It neutralizes the entity payloads, but not a literal ' , because the browser decodes ' back to ' before compiling the handler. The fixed templates are safe only because isValidURL() rejects the literal quote first.

The javascript: line is shown for completeness. The appended ?objectFit=cover makes it a syntax error, so it does not execute as written; the "> line does.

Any user with upload permission can store JavaScript that runs in the browser of any visitor, including administrators, of the YouPHPFlix2 page (on load, via the BigVideo iframe; or on clicking the trailer button) or a channel playlist. As with GHSA-v7vx, this allows session-riding admin actions.

Suggested fix direction:

Encode the value for a JavaScript string before HTML-escaping it at the three onclick sinks, e.g. htmlspecialchars(json_encode($url, JSON_HEX_APOS | JSON_HEX_QUOT), ENT_QUOTES) ; htmlspecialchars alone does not stop a literal ' there.

Use htmlspecialchars on the src attribute.

Reject non-http(s) URLs and quote/angle-bracket characters in setTrailer1() , so every consumer of trailer1 benefits.

AVideo/plugin/YouPHPFlix2/view/row_info.php Line 163 in 5e1701f ', '');return false;">

AVideo/plugin/YouPHPFlix2/view/row_info.php

AVideo/plugin/YouPHPFlix2/view/BigVideoButtons.php Line 34 in 5e1701f ', '');return false;">

AVideo/plugin/YouPHPFlix2/view/BigVideoButtons.php

AVideo/view/channelPlaylistItems.php Line 182 in 5e1701f ');">

AVideo/view/channelPlaylistItems.php

AVideo/plugin/YouPHPFlix2/view/BigVideo.php Line 29 in 5e1701f " frameborder="0" allowtransparency="true" allow="autoplay" tabindex="-1" aria-hidden="true">

AVideo/plugin/YouPHPFlix2/view/BigVideo.php

AVideo/objects/video.php Lines 4113 to 4122 in 5e1701f public function setTrailer1 ( $ trailer1 ) { if ( filter_var ( $ trailer1 , FILTER_VALIDATE_URL )) { $ new_trailer1 = $ trailer1 ; } else { $ new_trailer1 = '' ; } AVideoPlugin:: onVideoSetTrailer1 ( $ this , $ new_trailer1 ); $ this -> trailer1 = $ new_trailer1 ; }

AVideo/objects/video.php

Lines 4113 to 4122 in 5e1701f

VulnCheck (a CVE Numbering Authority) has reserved CVE-2026-105089 for this issue. Please reference it in the published advisory rather than requesting a new ID, so the issue does not end up with duplicate CVEs.

Extracted Entities