Impact
The AVideo application contains a reflected cross‑site scripting vulnerability in the showAlertMessage() function. The function inserts the raw Referer header value into a JavaScript comment without any encoding. An attacker can craft a Referer header that ends the comment sequence with */ and inject arbitrary HTML/JavaScript code. When a user loads the vulnerable page from the compromised referer, the injected script runs with the same origin as the site, potentially stealing session credentials, injecting malicious content, or hijacking the user’s interaction.
Affected Systems
WWBN AVideo is affected. No specific version numbers are listed in the advisory, so all releases of AVideo that include the referenced commit are considered vulnerable.
Risk and Exploitability
The CVSS score of 5.3 reflects a moderate (medium) risk level. The EPSS score is not available, so the exact likelihood of exploitation is unknown. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a web‑borne attack in which an attacker hosts a malicious page that sends a crafted Referer header to the vulnerable site; the injected script then executes in the context of any unsuspecting visitor who follows that link.
OpenCVE Enrichment