GHSA-xr9h-p2rc-rpqm

    Dashboard / Vulnerabilities / GHSA-xr9h-p2rc-rpqm

    GHSA-xr9h-p2rc-rpqm

    Published: 1 May 2023Last Modified: 16 Feb 2024

    Summary: WWBN/AVideo stored XSS vulnerability leads to takeover of any user's account, including admin's account

    Details: In AVideo, a normal user can make a Meeting Schedule where the user can invite another user in that Meeting, but I found out that it did not properly sanitize the malicious characters when creating a Meeting Room. This leads the attacker to put malicious scripts. Impact: Since any USER including the ADMIN can see the meeting room that was created by the attacker this can lead to cookie hijacking and takeover of any accounts without user interaction. Step to Reproduce: 1. As normal USER go to Meet -> Schedule https://demo.avideo.com/plugin/Meet/ 2. In "Meet topic" field put XSS payload Example: "><img src=x onerror=alert('Pawned+by+Gonz')> 3. Then click Save 4. Now as ADMIN go to Meet -> Schedule -> Upcoming https://demo.avideo.com/plugin/Meet/ 5. Then the XSS payload that normal USER created will be executed Video POC: https://youtu.be/Nke0Bmv5F-o

    Affected packages

    Package

    Name: wwbn/avideo

    Purl: pkg:composer/wwbn/avideo

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -12.4

    Affected versions

    10.4

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-xr9h-p2rc-rpqm | CVE-DB