CVE-2025-46410: XSS
A cross-site scripting (xss) vulnerability exists in the managerPlaylists PlaylistOwnerUsersId parameter functionality of WWBN AVideo 14.4 and dev master commit 8a8954ff. A specially crafted HTTP request can lead to arbitrary Javascript execution. An attacker can get a user to visit a webpage to trigger this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-46410?
The severity of CVE-2025-46410 has not been publicly classified, but cross-site scripting vulnerabilities are generally considered critical due to their potential for exploitation.
How do I fix CVE-2025-46410?
To fix CVE-2025-46410, update to the latest version of WWBN AVideo that addresses this cross-site scripting vulnerability.
What type of vulnerability is CVE-2025-46410?
CVE-2025-46410 is classified as a cross-site scripting (XSS) vulnerability.
What is affected by CVE-2025-46410?
CVE-2025-46410 affects WWBN AVideo version 14.4 and development master commit 8a8954ff.
What can an attacker do with CVE-2025-46410?
An attacker can execute arbitrary JavaScript in the context of a user's session by tricking them into visiting a specially crafted webpage.