Impact
The vulnerability allows an attacker who possesses any legitimate user account to insert malicious JavaScript into the User-Agent header. The LoginControl plugin stores that header in the login history without encoding it. When an administrator opens the history page, the script runs in the administrator’s browser and can execute arbitrary actions in the admin session, potentially leading to credential theft, defacement, or further compromise. This is a classic stored cross‑site scripting flaw identified as CWE‑79.
Affected Systems
WWBN AVideo, specifically the LoginControl plugin, is affected. The vulnerability exists in the code base identified by commit c3edcc274c389816d434acadac07ee78eaf330c1. No specific version range is provided, so any installation that contains this commit and has the LoginControl plugin enabled is vulnerable.
Risk and Exploitability
The CVSS score of 9.3 indicates critical risk. Exploitation requires an authenticated user to convey a crafted User‑Agent header and the target administrator browsing the login history. No disclosed EPSS score is available, but the absence of a KEV listing suggests no publicly known exploits yet. However, the flaw’s high impact and ease of triggering imply a significant attack potential for threat actors who can log in or compromise a user account.
OpenCVE Enrichment