PT-2025-30678 · Wwbn · Avideo

·

CVE-2025-46410

·

Published

2025-07-24

·

Updated

2025-07-29

CVSS v3.1

9.6

Critical

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions WWBN AVideo versions 14.4 dev master commit 8a8954ff
Description A cross-site scripting (xss) vulnerability exists in the managerPlaylists PlaylistOwnerUsersId parameter functionality. A specially crafted HTTP request can lead to arbitrary Javascript execution. An attacker can get a user to visit a webpage to trigger this vulnerability.
Recommendations WWBN AVideo version 14.4: Sanitize or encode user input for the managerPlaylists PlaylistOwnerUsersId parameter to prevent the injection of malicious scripts. dev master commit 8a8954ff: Sanitize or encode user input for the managerPlaylists PlaylistOwnerUsersId parameter to prevent the injection of malicious scripts.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-46410

Affected Products

Avideo