{"id":"CVE-2023-30860","aliases":["GHSA-xr9h-p2rc-rpqm"],"url":"https://o3.security/vulnerability/CVE-2023-30860","summary":"WWBN/AVideo stored XSS vulnerability leads to takeover of any user's account, including admin's account","details":"In AVideo, a normal user can make a Meeting Schedule where the user can invite another user in that Meeting, but I found out that it did not properly sanitize the malicious characters when creating a Meeting Room. This leads the attacker to put malicious scripts.\n\nImpact:\n\nSince any USER including the ADMIN can see the meeting room that was created by the attacker this can lead to cookie hijacking and takeover of any accounts without user interaction.\n\nStep to Reproduce:\n\n1. As normal USER go to Meet -> Schedule\n\nhttps://demo.avideo.com/plugin/Meet/\n\n2. In \"Meet topic\" field put XSS payload\n\nExample: \"><img src=x onerror=alert('Pawned+by+Gonz')>\n\n3. Then click Save\n\n4. Now as ADMIN go to Meet -> Schedule -> Upcoming\n\nhttps://demo.avideo.com/plugin/Meet/\n\n5. Then the XSS payload that normal USER created will be executed\n\n\n\nVideo POC: https://youtu.be/Nke0Bmv5F-o","published":"2023-05-08T18:04:09.703Z","modified":"2026-08-12T03:51:46.012275620Z","cvss":{"score":8,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":2,"affectedPackages":[{"ecosystem":"Packagist","name":"wwbn/avideo","fixedVersion":"12.4"}],"fix":null,"references":[{"type":"WEB","url":"https://youtu.be/Nke0Bmv5F-o"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/30xxx/CVE-2023-30860.json"},{"type":"ADVISORY","url":"https://github.com/WWBN/AVideo/security/advisories/GHSA-xr9h-p2rc-rpqm"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-30860"},{"type":"PACKAGE","url":"https://github.com/WWBN/AVideo"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:46.012275620Z"}}