A cross-site scripting (xss) vulnerability exists in the...
Critical severity
Unreviewed
Published
Jul 24, 2025
to the GitHub Advisory Database
Description
Published by the National Vulnerability Database
Jul 24, 2025
Published to the GitHub Advisory Database
Jul 24, 2025
A cross-site scripting (xss) vulnerability exists in the managerPlaylists PlaylistOwnerUsersId parameter functionality of WWBN AVideo 14.4 and dev master commit 8a8954ff. A specially crafted HTTP request can lead to arbitrary Javascript execution. An attacker can get a user to visit a webpage to trigger this vulnerability.
References