Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
internet-facing-service-vulnerabilitycredential-access-methodidentity-authentication-vulnerabilityopen-source-dependency-vulnerability

Client-Side Injection Flaws Expose Sessions and Sensitive Data in AVideo and dom-sanitizer

Updated 2mo agoFirst seen Apr 2, 20262 sources

Two newly disclosed web application flaws expose users to client-side data theft through content injection. In AVideo's TopMenu plugin, a stored cross-site scripting issue tracked as GHSA-GMPC-FXG2-VCMQ carries a CVSS 3.1 score of 6.1 and allows attackers to inject JavaScript that can read document.cookie, steal active session tokens, and impersonate users or administrators. Because the TopMenu component is rendered globally across the application, a malicious payload can execute for all site visitors, creating broad exposure and enabling follow-on attacks such as credential harvesting and fake login prompts.

A separate issue in rhukster/dom-sanitizer, tracked as GHSA-93VF-569F-22CQ, allows CSS injection through SVG style tags and is rated 4.7 under CVSS 3.1. The flaw can be exploited remotely without authentication when a victim renders a crafted SVG in a browser, potentially disclosing the victim's IP address, browser details, exact page URL, and sensitive DOM-resident data such as CSRF tokens or partial session identifiers. While the sanitizer flaw does not directly alter server-side state or disrupt availability, both disclosures highlight how server-side handling of untrusted content can be turned into browser-based theft of session and application data.

Share:
Client-Side Injection Flaws Expose Sessions and Sensitive Data in AVideo and dom-sanitizer
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

2 events from the most recent confirmed update back to the earliest known activity.

2 EVENTS
Apr 10, 20262mo ago

CSS injection vulnerability disclosed in rhukster/dom-sanitizer

A medium-severity CSS injection issue in PHP package rhukster/dom-sanitizer was publicly disclosed. The flaw, exploitable when a malicious SVG is rendered, could expose client-side data such as IP address, User-Agent, page URL, and potentially sensitive DOM content.

Apr 1, 20263mo ago

Stored XSS vulnerability disclosed in AVideo TopMenu plugin

A medium-severity stored cross-site scripting flaw affecting the AVideo TopMenu plugin was publicly reported. The issue could let attackers inject JavaScript that steals session tokens and potentially take over user or administrator accounts across globally rendered pages.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

1 LINKEDOpen in app
Affected products
1 linked
Avideo
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.