Impact
The LoginControl plugin in AVideo has a stored cross‑site scripting flaw where PGP encoding. An attacker who is authenticated can upload a crafted public key, causing injected the profile tab. The attack could lead to session hijacking, credential theft, or further malicious actions performed with the administrator’s privileges.
Affected Systems
The flaw affects the WWBN AVideo platform. Affected versions include any release that incorporates commit c3edcc274c389816d434acadac07ee78eaf330c1 or later before a patch is applied. There is no vendor‑specified version range in the advisory, so all recent installations are potentially vulnerable.
Risk and Exploitability
The CVSS score of 9.3 indicates high severity. EPSS data is not available, but the lack of KEV listing suggests no known widespread exploitation yet, yet the high CVSS indicates a serious vulnerability. The likely attack vector is via the web interface, requiring an authenticated user to upload a malicious public key. When an administrator later accesses the user profile, the stored script runs in that administrator’s session, potentially enabling unauthorized actions.
OpenCVE Enrichment