Vulnerability Details CVE-2023-47861
A cross-site scripting (xss) vulnerability exists in the channelBody.php user name functionality of WWBN AVideo 11.6 and dev master commit 15fed957fb. A specially crafted HTTP request can lead to arbitrary Javascript execution. An attacker can get a user to visit a webpage to trigger this vulnerability.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.003
EPSS Ranking 56.3%
CVSS Severity
CVSS v3 Score 9.0
Products affected by CVE-2023-47861
-
cpe:2.3:a:wwbn:avideo:11.6
-
cpe:2.3:a:wwbn:avideo:15fed957fb