CVE-2025-50128: XSS
A cross-site scripting (xss) vulnerability exists in the videoNotFound 404ErrorMsg parameter functionality of WWBN AVideo 14.4 and dev master commit 8a8954ff. A specially crafted HTTP request can lead to arbitrary Javascript execution. An attacker can get a user to visit a webpage to trigger this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-50128?
CVE-2025-50128 is classified as a high severity cross-site scripting (XSS) vulnerability.
How do I fix CVE-2025-50128?
To fix CVE-2025-50128, update to a patched version of WWBN AVideo that addresses this vulnerability.
What impact does CVE-2025-50128 have on users?
CVE-2025-50128 allows attackers to execute arbitrary JavaScript, potentially compromising user data and session security.
Which versions of WWBN AVideo are affected by CVE-2025-50128?
CVE-2025-50128 affects WWBN AVideo versions 14.4 and the dev master commit 8a8954ff.
How can an attacker exploit CVE-2025-50128?
An attacker can exploit CVE-2025-50128 by crafting a malicious HTTP request that triggers the XSS vulnerability when a user visits a compromised webpage.