PT-2025-43408 · Vdo.Ninja · Vdo.Ninja

Publicado

2025-10-22

·

Atualizado

2026-02-26

·

CVE-2025-62613

CVSS v4.0

6.9

Média

VetorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N
Name of the Vulnerable Software and Affected Versions VDO.Ninja versions 28.0 through 28.3
Description VDO.Ninja is a tool used to integrate remote video feeds into studio software via WebRTC. A reflected Cross-Site Scripting (XSS) issue exists in the examples/control.html file through the room parameter. The application does not properly sanitize input before rendering it in the Document Object Model (DOM), which allows for the injection and execution of malicious scripts.
Recommendations Update to version 28.4 or later.

Exploit

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2025-62613
GHSA-MP9C-CPCH-X73C

Produtos afetados

Vdo.Ninja