Horizon Alert
Summary of the vulnerability and why it matters
A stored cross-site scripting vulnerability exists in a video platform's login plugin, allowing an attacker with any valid login account to inject malicious scripts that execute in administrator browsers when viewing login history. This could enable script execution within an administrator's session.
- Injects scripts into login history.
- Impacts administrators viewing login history.
- Confirm relevance and exposure to your systems.
Attack Path
How an attacker could exploit the issue
An attacker with an existing login can exploit this vulnerability by injecting malicious scripts into the User-Agent header during the login process. When an administrator views the login history page, these scripts execute within the administrator's browser session, allowing the attacker to perform actions as the administrator.
- Entry condition: Attacker has a valid login account.
- Trigger point: Injecting script into User-Agent header.
- Resulting risk: Script execution in administrator session.
Live Threat
Current exploitation, exposure, and threat context
This vulnerability could allow an attacker to inject malicious scripts into the User-Agent header of login requests. When an administrator views the login history page, these scripts could execute within their browser session, potentially affecting the administrator's access and actions within the application.
- Administrator session data at risk.
- Malicious script in User-Agent header.
- Script execution within administrator session.
Operational Fix
Recommended remediation, mitigation, and detection steps
The WWBN AVideo platform, specifically the LoginControl plugin, is susceptible to stored cross-site scripting. This vulnerability requires an attacker with any valid login to have their malicious scripts executed within an administrator's browser when they access the login history. System owners and application administrators are likely responsible for addressing this issue by first identifying all instances of the affected technology, confirming their exposure and business criticality, and then planning remediation.
- Application owners should address this.
- Verify all AVideo admin access points.
- Plan vendor coordination for fix.