PT-2024-32306 · Unknown · Allvideo.Downloader.Browser

Edward Warren

·

Published

2024-11-11

·

Updated

2024-11-12

·

CVE-2024-46965

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions allvideo.downloader.browser (aka Fast Video Downloader: Browser) versions 1.6-RC1 and earlier
Description The issue allows an attacker to execute arbitrary JavaScript code via the allvideo.downloader.browser.DefaultBrowserActivity component. This enables the attacker to perform actions on the affected device, potentially leading to unauthorized access or data manipulation.
Recommendations For versions 1.6-RC1 and earlier, consider disabling the allvideo.downloader.browser.DefaultBrowserActivity component as a temporary workaround until a patch is available. Restrict access to this component to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-46965

Affected Products

Allvideo.Downloader.Browser