Vulnerability Details CVE-2023-48728
A cross-site scripting (xss) vulnerability exists in the functiongetOpenGraph videoName functionality of WWBN AVideo 11.6 and dev master commit 3c6bb3ff. A specially crafted HTTP request can lead to arbitrary Javascript execution. An attacker can get a user to visit a webpage to trigger this vulnerability.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.184
EPSS Ranking 95.0%
CVSS Severity
CVSS v3 Score 9.6
Products affected by CVE-2023-48728
-
cpe:2.3:a:wwbn:avideo:11.6
-
cpe:2.3:a:wwbn:avideo:3c6bb3ff