PT-2022-21453 · Wwbn · Wwbn Avideo

Claudio Bozzato

·

Published

2022-08-22

·

Updated

2022-08-24

·

CVE-2022-32771

CVSS v3.1

9.6

Critical

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions WWBN AVideo versions 11.6
Description A cross-site scripting issue exists in the footer alerts functionality. This allows arbitrary Javascript execution through a specially-crafted HTTP request. An attacker can exploit this by getting an authenticated user to send a crafted request. The issue arises from the success parameter being inserted into the document with insufficient sanitization.
Recommendations For WWBN AVideo version 11.6, consider disabling the footer alerts functionality until a patch is available to prevent exploitation. Restrict access to the success parameter to minimize the risk of arbitrary Javascript execution.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-32771

Affected Products

Wwbn Avideo