PT-2024-26240 · Wwbn · Avideo

Published

2024-05-13

·

Updated

2025-06-18

·

CVE-2024-34899

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions WWBN AVideo version 12.4
Description The issue is related to Cross Site Scripting (XSS) due to the lack of sanitization of the HTTP USER AGENT variable. In the view/about.php file, the website retrieves the user agent from the headers through $ SERVER['HTTP USER AGENT'] and echoes it without any sanitization, allowing an attacker to inject malicious scripts into the output of a web page. These scripts are then executed in the browser of anyone viewing that page.
Recommendations For WWBN AVideo version 12.4, consider sanitizing the HTTP USER AGENT variable in the view/about.php file to prevent XSS attacks. As a temporary workaround, restrict the output of the user agent information to minimize the risk of exploitation.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2024-34899
GHSA-F98P-2HC5-FM7V
GHSA-QVWG-C35P-RQHJ

Affected Products

Avideo