Impact
AVideo contains a reflected cross‑site scripting flaw in the userLogin.php page. An unauthenticated attacker can supply an error parameter that includes a closing script tag and a new script element, causing the browser to execute arbitrary JavaScript in the login page context. The attack can lead to theft of session cookies, credential phishing, or other client‑side compromise. The weakness is identified as CWE‑79, a classic input‑validation problem that allows script injection.
Affected Systems
The vulnerability is present in the AVideo application distributed by WWBN, specifically in revisions prior to commit c91b5975d. Any deployment using an older build that has not yet applied this commit is at risk.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity with an impact on confidentiality and integrity, but not availability. No EPSS score is available, and the vulnerability is not listed in the CISA KEV catalog, suggesting it is not widely exploited yet. The flaw is reachable via a crafted URL and does not require authentication, so the attack surface is broad within affected installations.
OpenCVE Enrichment