PT-2023-23017 · Avideo · Avideo
Gonzxph
·
Published
2023-05-01
·
Updated
2023-05-17
·
CVE-2023-30860
CVSS v3.1
8.0
High
| Vector | AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
AVideo versions prior to 12.4
Description
The issue arises from the failure to properly sanitize malicious characters when creating a Meeting Room in AVideo, allowing an attacker to insert malicious scripts. This can lead to cookie hijacking and takeover of any accounts, including those of administrators, as any user can see the meeting room created by the attacker.
Recommendations
For versions prior to 12.4, update to version 12.4 to resolve the issue. As a temporary workaround, consider restricting access to the Meeting Schedule feature until the update is applied. Additionally, avoid using the "Meet topic" field for any potentially malicious input until the issue is resolved.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Avideo