Impact
AVideo contains a stored cross‑site scripting flaw in the LiveLinks plugin; the title and description fields are saved without sanitization inject arbitrary JavaScript. The malicious script runs in any visitor’s browser that accesses the live‑link page, including administrators. Based on the description, it is inferred that this allows attackers to hijack sessions, steal data, or.
Affected Systems
The flaw exists in the AVideo LiveLinks plugin shipped with commit c3edcc274c389816d434acadac07ee78eaf330c1. The vulnerable component is maintained by WWBN and is part of the AVideo application.
Risk and Exploitability
With a CVSS score of 9.3 the vulnerability is classified as critical. The EPSS score is not available, but the presence of a persisted payload that triggers in visitors’ browsers suggests high exploitation potential, especially in environments where the canStream role is widely granted. The vulnerability is not listed in CISA KEV, yet it could be actively exploited in the wild given its severity and the ease of creating the malicious payload.
OpenCVE Enrichment