Horizon Alert
Summary of the vulnerability and why it matters
A stored cross-site scripting vulnerability exists within the LiveLinks plugin of the AVideo platform, allowing users with specific permissions to inject malicious scripts. These scripts can execute in the browsers of all visitors viewing the live-link page, potentially including administrators, thereby posing a broad risk to site integrity and user sessions.
- AVideo plugin allows script injection.
- It impacts all site visitors and admins.
- Confirm relevance and exposure for your AVideo instance.
Attack Path
How an attacker could exploit the issue
An attacker with the ability to stream content can inject malicious scripts into the title or description fields of a live link. These scripts then execute in the browsers of all visitors, including administrators, who view the live-link page.
- Publicly accessible, requires streaming permission.
- Stored script executes on visitor access.
- Cross-site scripting leading to site compromise.
Live Threat
Current exploitation, exposure, and threat context
A stored cross-site scripting vulnerability in the LiveLinks plugin could allow an authenticated user to inject malicious scripts. These scripts could execute in the browser of any visitor viewing a live-link page, including administrators, within the site's origin.
- Site content and visitor sessions could be affected.
- Malicious scripts execute in visitor browsers.
- Unauthorized actions may occur within the site.
Operational Fix
Recommended remediation, mitigation, and detection steps
The AVideo platform's LiveLinks plugin requires immediate attention from application owners and security teams. The first practical step is to identify all AVideo deployments, verify their exposure and business criticality, and confirm the accountable owner for each instance. This will allow for risk-based remediation planning, potentially involving vendor coordination or temporary mitigations if immediate patching is not feasible.
- Application owners must address this.
- Verify plugin usage and reachability first.
- Plan remediation based on confirmed exposure.