First published: Tue Apr 05 2022(Updated: )
Cross Site Scripting (XSS) vulnerability in objects/function.php in function getDeviceID in WWBN AVideo through 11.6, via the yptDevice parameter to view/include/head.php.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
WWBN AVideo | <=11.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-27462 is classified as a medium severity Cross Site Scripting (XSS) vulnerability.
To fix CVE-2022-27462, update WWBN AVideo to version 11.7 or later.
CVE-2022-27462 affects all versions of WWBN AVideo up to and including version 11.6.
CVE-2022-27462 is associated with Cross Site Scripting (XSS) attacks.
CVE-2022-27462 can allow attackers to execute malicious scripts in the context of a victim's browser, potentially compromising user data.