What is CVE-2026-72747?
CVE-2026-72747 is a stored XSS vulnerability in the AVideo platform due to unsanitized phone field during user registration. Unauthenticated attackers can inject malicious JavaScript via this field which persists in the database. When administrators view the users management page, the script executes via innerHTML rendering.
Azərbaycanca: CVE-2026-72747, AVideo platformunun istifadəçi qeydiyyatı zamanı telefon sahəsini təmizləməməsi nəticəsində yaranan saxlanılmış XSS zəifliyidir. Bu boşluq autentifikasiya olunmamış hücumçulara JavaScript kodu yerləşdirməyə imkan verir. Administrativ istifadəçi idarəetmə səhifəsinə daxil olduqda, skript işə düşür.
Related CVEs
link basis: same weakness class CWE-79
FAQ2
Does exploiting CVE-2026-72747 require the attacker to be authenticated on the AVideo platform?
No, unauthenticated attackers can inject malicious JavaScript code into the phone field during user registration.
Under what condition does the stored XSS payload in CVE-2026-72747 execute?
The script executes when an administrative user accesses the users management page, via innerHTML rendering.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.