PT-2025-30680 · Wwbn · Avideo

·

CVE-2025-50128

·

Published

2025-07-24

·

Updated

2025-07-29

CVSS v3.1

9.6

Critical

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions WWBN AVideo versions 14.4 WWBN AVideo dev master commit 8a8954ff
Description A cross-site scripting (xss) vulnerability exists due to the videoNotFound 404ErrorMsg parameter functionality. A specially crafted HTTP request can lead to arbitrary Javascript execution. An attacker can get a user to visit a webpage to trigger this issue.
Recommendations WWBN AVideo version 14.4: Address the vulnerability in the videoNotFound 404ErrorMsg parameter to prevent arbitrary Javascript execution. WWBN AVideo dev master commit 8a8954ff: Address the vulnerability in the videoNotFound 404ErrorMsg parameter to prevent arbitrary Javascript execution.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-50128

Affected Products

Avideo