PT-2024-32305 · Unknown · All Video Downloader

Edward Warren

·

Published

2024-11-11

·

Updated

2024-11-12

·

CVE-2024-46964

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions All Video Downloader versions through 11.28
Description The issue allows an attacker to execute arbitrary JavaScript code via the com.video.downloader.all.StartActivity component.
Recommendations For All Video Downloader versions through 11.28, consider disabling the com.video.downloader.all.StartActivity component as a temporary workaround until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-46964

Affected Products

All Video Downloader