CVE-2022-27462: XSS
Published Apr 5, 2022
·Updated
Cross Site Scripting (XSS) vulnerability in objects/function.php in function getDeviceID in WWBN AVideo through 11.6, via the yptDevice parameter to view/include/head.php.
Affected Software
1 affected component
WWBN AVideo<=11.6
Remediation
Event History
Apr 5, 2022
CVE Published
via MITRE·03:37 PM
Data Sourced
via MITRE·03:37 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2022-27462?
CVE-2022-27462 is classified as a medium severity Cross Site Scripting (XSS) vulnerability.
2
How do I fix CVE-2022-27462?
To fix CVE-2022-27462, update WWBN AVideo to version 11.7 or later.
3
What software is affected by CVE-2022-27462?
CVE-2022-27462 affects all versions of WWBN AVideo up to and including version 11.6.
4
What kind of attack is CVE-2022-27462 associated with?
CVE-2022-27462 is associated with Cross Site Scripting (XSS) attacks.
5
How can CVE-2022-27462 impact users?
CVE-2022-27462 can allow attackers to execute malicious scripts in the context of a victim's browser, potentially compromising user data.