HIGHVulnerability
Verified
Global

NVD HIGH: CVE-2026-72747 — AVideo fails to sanitize the phone field during user registration, allowing unau...

·Source: NIST NVD

Updated:

Executive Summary

AVideo fails to sanitize the phone field during user registration, allowing unauthenticated attackers to inject malicious JavaScript that persists in the database. When administrators visit the users management page, the unsanitized phone value is rendered via innerHTML, executing the injected script in the admin's browser session.

Analysis

AVideo fails to sanitize the phone field during user registration, allowing unauthenticated attackers to inject malicious JavaScript that persists in the database. When administrators visit the users management page, the unsanitized phone value is rendered via innerHTML, executing the injected script in the admin's browser session. CVSS Score: 7.2. Published: 2026-08-11T13:19:05.663.

Indicators of Compromise (1)

CVE (1)
CVE-2026-72747
Source Attribution

Originally published by NIST NVD on Aug 11, 2026. Verified by: NIST.

Related Threats