Impact
WWBN AVideo includes a reflected cross‑site scripting flaw in plugin/Live/confirmLivePassword.php. The script takes the unauthenticated GET parameter u, which is not sanitized by the security filter, and interpolates it directly into an img src attribute. An attacker can inject a double‑quote and a malicious tag with an onerror handler, causing any browser that loads the crafted link—including administrators—to execute arbitrary JavaScript in the site's origin.
Affected Systems
The vulnerability affects the WWBN AVideo platform, specifically the confirmLivePassword.php file under the Live plugin. Any instance of AVideo built from commit c3edcc274c389816d434acadac07ee78eaf330c1 or any earlier version that has not applied a subsequent patch is susceptible. No specific patch version was available installations running the affected code base remain at risk.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity. EPSS information is not available, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is remote: an adversary only needs to craft a URL containing a malicious u parameter and entice a user to click it. Authentication is not required for the vulnerable endpoint. The impact is confined to the victim's browser session and can lead to session hijacking, credential theft, or phishing. Due to the lack of a current public fix, the exploit is theoretically straightforward for attackers who can generate and spread malicious links.
OpenCVE Enrichment