2026-04-07 19:22:07
GitHub_M
PUBLISHED
WWBN AVideo is an open source video platform. In versions 26.0 and prior, AVideos EPG (Electronic Program Guide) feature parses XML from user-controlled URLs and renders programme titles directly into HTML without any sanitization or escaping. A user with upload permission can set a videos epg_link to a malicious XML file whose