PT-2023-23017 · Avideo · Avideo

Gonzxph

·

Published

2023-05-01

·

Updated

2023-05-17

·

CVE-2023-30860

CVSS v3.1

8.0

High

VectorAV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions AVideo versions prior to 12.4
Description The issue arises from the failure to properly sanitize malicious characters when creating a Meeting Room in AVideo, allowing an attacker to insert malicious scripts. This can lead to cookie hijacking and takeover of any accounts, including those of administrators, as any user can see the meeting room created by the attacker.
Recommendations For versions prior to 12.4, update to version 12.4 to resolve the issue. As a temporary workaround, consider restricting access to the Meeting Schedule feature until the update is applied. Additionally, avoid using the "Meet topic" field for any potentially malicious input until the issue is resolved.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2023-30860
GHSA-XR9H-P2RC-RPQM

Affected Products

Avideo