Impact
WWBN AVideo includes a reflected cross‑site scripting flaw in the confirmLivePassword.php page. The code copies REQUEST_URI can embed a quote character in a malicious URL to break out of the attribute context and inject JavaScript event handlers that run in the victim’s browser while staying within the site origin. The weakness maps to CWE‑79, a vulnerability that allows attackers to execute client‑side scripts in the context of the affected site.
Affected Systems
The affected vendor is WWBN, with the product name AVideo. No specific version information is listed in the CVE, so any deployment of AVideo that includes the confirmLivePassword.php script before the fix is potentially vulnerable.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate impact level. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, indicating that no publicly disclosed exploits are known at this time. Attackers can exploit this by crafting a malicious URL that points to confirmLivePassword.php, which the victim clicks or visits, causing the injected script to run within the site origin. The risk is confined to the user’s browser session and does not directly compromise the server.
OpenCVE Enrichment