CVE-2023-48728
wwbn avideo Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Record summary
CVE-2023-48728 has a selected CVSS score of 9.6 (critical); EIP currently links 1 Nuclei template.
Description
A cross-site scripting (xss) vulnerability exists in the functiongetOpenGraph videoName functionality of WWBN AVideo 11.6 and dev master commit 3c6bb3ff. A specially crafted HTTP request can lead to arbitrary Javascript execution. An attacker can get a user to visit a webpage to trigger this vulnerability.
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Jun 7, 2025 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Jan 10, 2024 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
AVideoBrowse WWBN / AVideo | CVE List, VulnCheck | 11.6 | affected |
| dev master commit 3c6bb3ff | affected |
Nuclei templates
1ProjectDiscoveryMEDIUMWWBN AVideo 11.6 - Cross-Site ScriptingCVSS 6.1
A reflected XSS vulnerability exists in the functiongetOpenGraph videoName functionality of WWBN AVideo 11.6 and dev master commit 3c6bb3ff, allowing arbitrary Javascript execution.
Impact
Successful exploitation could lead to unauthorized access to sensitive information or account takeover.
Remediation
Sanitize and validate user input to prevent XSS attacks.
Source: ProjectDiscovery