Impact
The flaw permits an attacker to embed arbitrary JavaScript within the url2Embed.json.php endpoint by submitting a URL that contains unescaped HTML metacharacters. Because the input is reflected unchanged in the response, any victim who loads the crafted link will have the malicious script executed inside their browser, allowing cookie theft, CSRF token theft, or other client-side exploitation.
Affected Systems
The vulnerability is present in the WWBN AVideo application. No specific version range is supplied, so any deployed instance of AVideo is potentially affected until a patch is applied.
Risk and Exploitability
The CVSS score of 5.3 denotes moderate severity, and the EPSS score is not available, though the issue is not listed in the CISA KEV catalog. An unauthenticated attacker can exploit this flaw simply by delivering a carefully constructed URL; the attack requires user interaction to open the link and is purely client-side. Without a patch, the risk remains until remediation is performed.
OpenCVE Enrichment