PT-2022-19188 · Wwbn · Avideo

Claudio Bozzato

·

Published

2022-08-22

·

Updated

2022-08-26

·

CVE-2022-28712

CVSS v3.1

9.0

Critical

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions WWBN AVideo versions 11.6 and dev master commit 3f7c0364
Description A cross-site scripting issue exists in the videoAddNew functionality, allowing arbitrary Javascript execution through a specially-crafted HTTP request. This can be triggered by getting an authenticated user to send the crafted request.
Recommendations For WWBN AVideo version 11.6, update to a version that fixes this issue. For WWBN AVideo dev master commit 3f7c0364, update to a commit that includes the fix for this issue. As a temporary workaround, consider restricting access to the videoAddNew functionality until a patch is available.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2022-28712

Affected Products

Avideo