Horizon Alert
Summary of the vulnerability and why it matters
A stored cross-site scripting vulnerability in WWBN AVideo allows authenticated users to inject malicious code through specially crafted video titles. This could potentially lead to the execution of arbitrary HTML and script content on pages viewed by other users, impacting site integrity and user experience.
- The issue allows code injection via video titles.
- This impacts user-facing video content pages.
- Confirm WWBN AVideo relevance and exposure.
Attack Path
How an attacker could exploit the issue
An attacker with uploader privileges can inject malicious HTML into video titles, even if the content is doubly encoded. This markup can then execute when users view trending, gallery, embed, or playlist pages, potentially leading to unauthorized actions or information disclosure.
- Authenticated uploader access required.
- Stored HTML in video titles.
- Risk of code execution in user views.
Live Threat
Current exploitation, exposure, and threat context
This vulnerability could allow authenticated users to inject HTML into video titles, which may then execute as stored cross-site scripting on pages like trending, gallery, and embed views. The impact is contingent on the specific configuration and exposure of these pages.
- Stored HTML in video titles.
- Injected HTML executes in user browsers.
- Compromised user trust and session integrity.
Operational Fix
Recommended remediation, mitigation, and detection steps
This vulnerability likely affects application owners and platform teams responsible for WWBN AVideo deployments. The first step is to identify all instances of WWBN AVideo, confirm their accessibility and business criticality, and then identify the accountable owner for remediation planning.
- Application owners should own the issue.
- Verify public or internal reachability first.
- Plan remediation or implement temporary risk reduction.