GHSA-2fch-hv74-fgw9
Dashboard / Vulnerabilities / GHSA-2fch-hv74-fgw9
GHSA-2fch-hv74-fgw9
Summary: Cross site scripting (XSS) in wwbn/avideo
Details: Description: While making an account in demo.avideo.com I found a parameter "?success=" which did not sanitize any symbol character properly which leads to XSS attack. Impact: Since there's an Admin account on demo.avideo.com attacker can use this attack to Takeover the admin's account Step to Reproduce: 1. Click the link below [https://demo.avideo.com/user?success="><img](https://demo.avideo.com/user?success=%22%3E%3Cimg) src=x onerror=alert(document.cookie)> 2. Then XSS will be executed
References: https://github.com/WWBN/AVideo/security/advisories/GHSA-2fch-hv74-fgw9, https://github.com/WWBN/AVideo
Affected packages
Package
Name: wwbn/avideo
Purl: pkg:composer/wwbn/avideo
Affected ranges
Type: ECOSYSTEM
Events:
