{"id":"GHSA-2fch-hv74-fgw9","aliases":[],"url":"https://o3.security/vulnerability/GHSA-2fch-hv74-fgw9","summary":"Cross site scripting (XSS) in wwbn/avideo","details":"Description:\n\nWhile making an account in demo.avideo.com I found a parameter \"?success=\" which did not sanitize any symbol character properly which leads to XSS attack.\n\nImpact:\n\nSince there's an Admin account on demo.avideo.com attacker can use this attack to Takeover the admin's account\n\nStep to Reproduce:\n\n1. Click the link below\n\n[https://demo.avideo.com/user?success=\"><img](https://demo.avideo.com/user?success=%22%3E%3Cimg) src=x onerror=alert(document.cookie)>\n\n2. Then XSS will be executed","published":"2023-04-26T19:42:30Z","modified":"2024-12-03T05:55:29.548295Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"wwbn/avideo","fixedVersion":"12.4"}],"fix":null,"references":[{"type":"WEB","url":"https://github.com/WWBN/AVideo/security/advisories/GHSA-2fch-hv74-fgw9"},{"type":"PACKAGE","url":"https://github.com/WWBN/AVideo"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2024-12-03T05:55:29.548295Z"}}