Impact
A stored cross‑site scripting vulnerability exists in AVideo’s UserGroups::setGroup_name() where the group_name field is not properly sanitized. Administrators with canAdminUserGroups permission can inject malicious HTML and JavaScript that executes in the browser of other administrators when they open the user manager interface. This flaw allows an attacker to execute arbitrary client‑side code, potentially hijacking admin sessions, manipulating UI, or collecting information while an administrator is logged in.
Affected Systems
The affected product is WWBN AVideo. No specific version information is provided, so any installation that uses the vulnerable UserGroups implementation is potentially impacted.
Risk and Exploitability
The CVSS base score is 9.2, indicating a high‑severity flaw. The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog. Because the flaw requires administrator privileges, the likely attack vector is through an authenticated session where an attacker can create or modify a user group. Once the malicious script runs in their browser, giving the attacker client‑side execution capabilities.
OpenCVE Enrichment