CVE-2022-28712: XSS
Published Aug 22, 2022
·Updated
A cross-site scripting (xss) vulnerability exists in the videoAddNew functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. A specially-crafted HTTP request can lead to arbitrary Javascript execution. An attacker can get an authenticated user to send a crafted HTTP request to trigger this vulnerability.
Affected Software
1 affected component
WWBN AVideo=11.6
Event History
Aug 22, 2022
CVE Published
via MITRE·06:22 PM
Data Sourced
via MITRE·06:22 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2022-28712?
CVE-2022-28712 is rated as a medium severity cross-site scripting vulnerability.
2
How do I fix CVE-2022-28712?
To fix CVE-2022-28712, upgrade WWBN AVideo to a version newer than 11.6 that addresses this vulnerability.
3
What systems are affected by CVE-2022-28712?
CVE-2022-28712 affects WWBN AVideo version 11.6 and earlier versions.
4
What type of vulnerability is CVE-2022-28712?
CVE-2022-28712 is a cross-site scripting (XSS) vulnerability.
5
How can an attacker exploit CVE-2022-28712?
An attacker can exploit CVE-2022-28712 by sending a specially-crafted HTTP request to an authenticated user.