9.6
/ 10
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Description
A cross-site scripting (xss) vulnerability exists in the userLogin cancelUri parameter functionality of WWBN AVideo 14.4 and dev master commit 8a8954ff. A specially crafted HTTP request can lead to arbitrary Javascript execution. An attacker can get a user to visit a webpage to trigger this vulnerability.
Basic Information
ID
CVE-2025-41420
Source
talos
Published
Jul 24, 2025 at 15:11
Modified
Jul 24, 2025 at 15:41
Affected Product
Vendor
WWBN
Product
AVideo
Version
14.4
Affected Versions
WWBN AVideo 14.4
WWBN AVideo dev master commit 8a8954ff
WWBN AVideo dev master commit 8a8954ff