Impact
A video‑analytics application retains the exact User‑Agent string sent by a client in a database field without sanitization. The string is later rendered inside an unescaped DataTables cell, allowing an attacker’s malicious HTML or script to execute in the browser of anyone who views the statistics page. This delivers the attacker’s script to a privileged user’s authenticated session, potentially exposing session cookies, personal data, or enabling further privilege escalation. The weakness is a classic stored cross‑site scripting flaw (CWE‑79).
Affected Systems
The vulnerability exists in AVideo version 29.0 and earlier (revision e01e41ecc). No patch has been released as of the advisory; the issue is present in all installations of the affected releases that expose the unprotected view‑counter endpoint.
Risk and Exploitability
The vulnerability carries a CVSS score of 5.3, indicating moderate severity, while its EPSS score is less than 1 %, implying a low probability of exploitation at the present time. It is not listed in the CISA KEV catalog. Attackers can inject the malicious payload by simply sending a crafted User‑Agent header to the unauthenticated view‑counter endpoint; the stored data is later delivered to a logged‑in administrator when the statistics page is rendered. The threat is limited to browsers running the application and requires no special privileges beyond matching a known endpoint. The high‑impact nature of executing code in an authenticated context, however, warrants prompt remediation once a patch becomes available.
OpenCVE Enrichment