PT-2025-30678 · Wwbn · Avideo
Claudio Bozzato
·
Published
2025-07-24
·
Updated
2025-07-29
·
CVE-2025-46410
CVSS v3.1
9.6
Critical
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
WWBN AVideo versions 14.4
dev master commit 8a8954ff
Description
A cross-site scripting (xss) vulnerability exists in the
managerPlaylists PlaylistOwnerUsersId parameter functionality. A specially crafted HTTP request can lead to arbitrary Javascript execution. An attacker can get a user to visit a webpage to trigger this vulnerability.Recommendations
WWBN AVideo version 14.4: Sanitize or encode user input for the
managerPlaylists PlaylistOwnerUsersId parameter to prevent the injection of malicious scripts.
dev master commit 8a8954ff: Sanitize or encode user input for the managerPlaylists PlaylistOwnerUsersId parameter to prevent the injection of malicious scripts.Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Avideo