PT-2022-21453 · Wwbn · Wwbn Avideo
Claudio Bozzato
·
Published
2022-08-22
·
Updated
2022-08-24
·
CVE-2022-32771
CVSS v3.1
9.6
Critical
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
WWBN AVideo versions 11.6
Description
A cross-site scripting issue exists in the footer alerts functionality. This allows arbitrary Javascript execution through a specially-crafted HTTP request. An attacker can exploit this by getting an authenticated user to send a crafted request. The issue arises from the
success parameter being inserted into the document with insufficient sanitization.Recommendations
For WWBN AVideo version 11.6, consider disabling the footer alerts functionality until a patch is available to prevent exploitation. Restrict access to the
success parameter to minimize the risk of arbitrary Javascript execution.Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Wwbn Avideo