CVE-2022-32771: XSS
A cross-site scripting (xss) vulnerability exists in the footer alerts functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. A specially-crafted HTTP request can lead to arbitrary Javascript execution. An attacker can get an authenticated user to send a crafted HTTP request to trigger this vulnerability.This vulnerability arrises from the "success" parameter which is inserted into the document with insufficient sanitization.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-32771?
CVE-2022-32771 is classified as a high severity cross-site scripting (XSS) vulnerability.
How do I fix CVE-2022-32771?
To fix CVE-2022-32771, upgrade to a non-vulnerable version of WWBN AVideo, such as 12.0 or later.
What software is affected by CVE-2022-32771?
CVE-2022-32771 affects WWBN AVideo version 11.6 and earlier.
What are the potential impacts of CVE-2022-32771?
CVE-2022-32771 allows an attacker to execute arbitrary JavaScript on behalf of an authenticated user.
How can an attacker exploit CVE-2022-32771?
An attacker can exploit CVE-2022-32771 by crafting a malicious HTTP request that targets the footer alerts functionality.