Record summary

CVE-2023-48728 has a selected CVSS score of 9.6 (critical); EIP currently links 1 Nuclei template.

Description

A cross-site scripting (xss) vulnerability exists in the functiongetOpenGraph videoName functionality of WWBN AVideo 11.6 and dev master commit 3c6bb3ff. A specially crafted HTTP request can lead to arbitrary Javascript execution. An attacker can get a user to visit a webpage to trigger this vulnerability.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Jun 7, 2025 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationPoC
AutomatableYes
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Jan 10, 2024 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus
CVE List, VulnCheck11.6affected
dev master commit 3c6bb3ffaffected

Nuclei templates

1
ProjectDiscoveryMEDIUMWWBN AVideo 11.6 - Cross-Site ScriptingCVSS 6.1

A reflected XSS vulnerability exists in the functiongetOpenGraph videoName functionality of WWBN AVideo 11.6 and dev master commit 3c6bb3ff, allowing arbitrary Javascript execution.

Impact

Successful exploitation could lead to unauthorized access to sensitive information or account takeover.

Remediation

Sanitize and validate user input to prevent XSS attacks.

WeaknessesCWE-79
Authorsritikchaddha
Template tagscvecve2023avideoxssvkevvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:wwbn:avideo:3c6bb3ff:*:*:*:*:*:*:*
Shodan: html:"AVideo"

Source: ProjectDiscovery

References

3