CVE-2025-41420: XSS
A cross-site scripting (xss) vulnerability exists in the userLogin cancelUri parameter functionality of WWBN AVideo 14.4 and dev master commit 8a8954ff. A specially crafted HTTP request can lead to arbitrary Javascript execution. An attacker can get a user to visit a webpage to trigger this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-41420?
CVE-2025-41420 is classified as a high severity cross-site scripting (XSS) vulnerability.
How do I fix CVE-2025-41420?
To mitigate CVE-2025-41420, users should upgrade to the latest version of WWBN AVideo that addresses this XSS vulnerability.
What impact does CVE-2025-41420 have on users?
CVE-2025-41420 can lead to arbitrary JavaScript execution, potentially compromising user session information and data.
What software is affected by CVE-2025-41420?
CVE-2025-41420 affects WWBN AVideo version 14.4 and the development master commit 8a8954ff.
Can CVE-2025-41420 be exploited remotely?
Yes, an attacker can exploit CVE-2025-41420 by crafting a malicious HTTP request that targets the userLogin cancelUri parameter.