Skip to content

XSS

High
DanielnetoDotCom published GHSA-2fch-hv74-fgw9 Apr 26, 2023

Package

No package listed

Affected versions

< 12.3

Patched versions

12.4

Description

Description:

While making an account in demo.avideo.com I found a parameter "?success=" which did not sanitize any symbol character properly which leads to XSS attack.

Impact:

Since there's an Admin account on demo.avideo.com attacker can use this attack to Takeover the admin's account

Step to Reproduce:

  1. Click the link below

https://demo.avideo.com/user?success="><img src=x onerror=alert(document.cookie)>

  1. Then XSS will be executed

Severity

High

CVE ID

CVE-2023-25314

Weaknesses

No CWEs

Credits