Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2023-48728

Опубликовано: 10 янв. 2024
Источник: nvd
CVSS3: 9.6
CVSS3: 6.1
EPSS Средний

Описание

A cross-site scripting (xss) vulnerability exists in the functiongetOpenGraph videoName functionality of WWBN AVideo 11.6 and dev master commit 3c6bb3ff. A specially crafted HTTP request can lead to arbitrary Javascript execution. An attacker can get a user to visit a webpage to trigger this vulnerability.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:wwbn:avideo:3c6bb3ff:*:*:*:*:*:*:*
cpe:2.3:a:wwbn:avideo:11.6:*:*:*:*:*:*:*

EPSS

Процентиль: 95%
0.17352
Средний

9.6 Critical

CVSS3

6.1 Medium

CVSS3

Дефекты

CWE-79
CWE-79

Связанные уязвимости

CVSS3: 9.6
github
около 2 лет назад

A cross-site scripting (xss) vulnerability exists in the functiongetOpenGraph videoName functionality of WWBN AVideo 11.6 and dev master commit 3c6bb3ff. A specially crafted HTTP request can lead to arbitrary Javascript execution. An attacker can get a user to visit a webpage to trigger this vulnerability.

EPSS

Процентиль: 95%
0.17352
Средний

9.6 Critical

CVSS3

6.1 Medium

CVSS3

Дефекты

CWE-79
CWE-79