PT-2025-43408 · Vdo.Ninja · Vdo.Ninja
Publicado
2025-10-22
·
Atualizado
2026-02-26
·
CVE-2025-62613
CVSS v4.0
6.9
Média
| Vetor | AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N |
Name of the Vulnerable Software and Affected Versions
VDO.Ninja versions 28.0 through 28.3
Description
VDO.Ninja is a tool used to integrate remote video feeds into studio software via WebRTC. A reflected Cross-Site Scripting (XSS) issue exists in the examples/control.html file through the
room parameter. The application does not properly sanitize input before rendering it in the Document Object Model (DOM), which allows for the injection and execution of malicious scripts.Recommendations
Update to version 28.4 or later.
Exploit
Correção
XSS
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Vdo.Ninja