www.vulncheck.com Stored XSS Vulnerabilities in Wwbn Avideo Affect Multiple Versions
Article Content
- •Two stored XSS vulnerabilities identified in Wwbn Avideo versions 12.4 to 29.2.0.
- •Vulnerabilities allow execution of arbitrary scripts in user browsers.
- •No active exploitation reported; users should prioritize patching.
Wwbn Avideo versions 12.4 through 29.2.0 are affected by two stored cross-site scripting (XSS) vulnerabilities. The first vulnerability involves double-encoded video titles, while the second is related to the Trailer1 in YouPHPFlix2 templates. Both vulnerabilities are categorized under CWE-79, indicating improper neutralization of input during web page generation. The vulnerabilities could allow attackers to execute arbitrary scripts in the context of the user's browser. As of now, there are no reports of, but users are advised to prioritize patching. GitHub Security Advisories have been issued for both vulnerabilities, identified as GHSA-q62w-927x-vhhf and GHSA-6wfr-c7fw-4xvw. Administrators are encouraged to review their systems and apply necessary updates to mitigate potential risks.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Common questions
Which versions of Wwbn Avideo are affected?
Is there any active exploitation of these vulnerabilities?
What actions should be taken to mitigate these vulnerabilities?
Continue Reading
Twitch Chat Messages Exploit OBS Studio via Chromium Vulnerability A vulnerability in OBS Studio allows malicious Twitch chat messages to execute native code on streamers' Windows PCs. This exploit targets users running OBS Studio version 32.2.2 or older, leveraging a cross-site scripting (XSS) flaw in custom overlays that render viewer messages as unsanitized HTML. The attack…