A cross-site scripting (xss) vulnerability exists in the managerPlaylists PlaylistOwnerUsersId parameter functionality of WWBN AVideo 14.4 and dev mas...
Description
A cross-site scripting (xss) vulnerability exists in the managerPlaylists PlaylistOwnerUsersId parameter functionality of WWBN AVideo 14.4 and dev master commit 8a8954ff. A specially crafted HTTP requ...
AI Analyst Comment
Remediation
Update A Multiple Products to the latest version. Check vendor security advisory for specific patch details. Monitor for exploitation attempts and review access logs.
---METADATA---
VENDOR: WWBN
PRODUCT: AVideo
AFFECTED_VERSIONS: 14.4 and dev master commit 8a8954ff
CONFIDENCE: high
MISSING: patch
---END_METADATA---
Description Summary:
A cross-site scripting (XSS) vulnerability exists in the managerPlaylists PlaylistOwnerUsersId parameter of WWBN AVideo, allowing for potential malicious script injection.
Executive Summary:
A critical cross-site scripting vulnerability in WWBN AVideo 14.4 poses a significant risk of unauthorized script execution within the user's browser context.
Vulnerability Details
CVE-ID: CVE-2025-46410
Affected Software: WWBN AVideo
Affected Versions: 14.4 and dev master commit 8a8954ff
Vulnerability: This is a cross-site scripting (XSS) vulnerability located in the
managerPlaylistsfunctionality, specifically within thePlaylistOwnerUsersIdparameter. Based on the functional area, this likely requires an authenticated session to exploit.Business Impact
Successful exploitation of this XSS vulnerability could allow an attacker to hijack user sessions, perform unauthorized actions on behalf of the user, or deface the application interface. Given the CVSS score of 9.6, this flaw represents a critical risk to data integrity and user confidentiality, potentially leading to full account takeover if administrative sessions are compromised.
Remediation Plan
Immediate Action: Upgrade to the latest version of AVideo provided by the vendor to remediate the vulnerable parameter.
Proactive Monitoring: Review web server and application access logs for unusual patterns or suspicious strings within URL parameters related to playlist management.
Compensating Controls: Deploy a Web Application Firewall (WAF) with strict XSS filtering rules to inspect and block malicious payloads targeting the
PlaylistOwnerUsersIdparameter.Exploitation Status
Public Exploit Available: Not specified
Analyst Notes: As of Jul 24, 2025, there is no public information indicating active exploitation of this vulnerability. However, due to the nature of the flaw, the potential for exploitation is high.
Analyst Recommendation
The high CVSS score of 9.6 underscores the severity of this vulnerability. Organizations using AVideo must prioritize upgrading to the latest patched version to neutralize the risk of unauthorized script execution and potential session compromise.