{"id":"GHSA-2fch-hv74-fgw9","summary":"Cross site scripting (XSS) in wwbn/avideo","details":"Description:\n\nWhile making an account in demo.avideo.com I found a parameter \"?success=\" which did not sanitize any symbol character properly which leads to XSS attack.\n\nImpact:\n\nSince there's an Admin account on demo.avideo.com attacker can use this attack to Takeover the admin's account\n\nStep to Reproduce:\n\n1. Click the link below\n\n[https://demo.avideo.com/user?success=\"\u003e\u003cimg](https://demo.avideo.com/user?success=%22%3E%3Cimg) src=x onerror=alert(document.cookie)\u003e\n\n2. Then XSS will be executed","modified":"2024-12-03T05:55:29.548295Z","published":"2023-04-26T19:42:30Z","database_specific":{"nvd_published_at":null,"cwe_ids":["CWE-79"],"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2023-04-26T19:42:30Z"},"references":[{"type":"WEB","url":"https://github.com/WWBN/AVideo/security/advisories/GHSA-2fch-hv74-fgw9"},{"type":"PACKAGE","url":"https://github.com/WWBN/AVideo"}],"affected":[{"package":{"name":"wwbn/avideo","ecosystem":"Packagist","purl":"pkg:composer/wwbn/avideo"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"12.4"}]}],"versions":["10.4","10.8","11","11.1","11.1.1","11.5","11.6"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/04/GHSA-2fch-hv74-fgw9/GHSA-2fch-hv74-fgw9.json"}}],"schema_version":"1.9.0"}