Horizon Alert
Summary of the vulnerability and why it matters
A vulnerability in the AVideo Bookmark plugin allows unauthorized scripts to run when visitors view specific videos. This occurs because chapter names are not properly secured before being displayed, enabling malicious code injection. The main concern is confirming if this specific AVideo plugin is in use and potentially exposed.
- Unsecured chapter names permit script injection.
- It affects public video watch pages.
- Confirm relevance and exposure of this plugin.
Attack Path
How an attacker could exploit the issue
An attacker could inject malicious scripts into a video's bookmark name, which is then displayed to all visitors of that video. This vulnerability allows the attacker to execute arbitrary code within the AVideo origin for any user viewing the compromised video.
- Requires a video owner's account.
- Inject script into bookmark name.
- Leads to cross-site scripting execution.
Live Threat
Current exploitation, exposure, and threat context
This vulnerability could impact user experience by allowing malicious scripts to execute within a visitor's browser when viewing a video. The risk is that these scripts could potentially disrupt the normal functionality of the watch page or lead to unintended actions for the user.
- User-facing watch pages at risk.
- Malicious scripts injected via bookmark names.
- Disrupted user experience and potential actions.
Operational Fix
Recommended remediation, mitigation, and detection steps
The AVideo platform's Bookmark plugin is susceptible to stored cross-site scripting, allowing malicious scripts to execute within the origin of any visitor viewing a video with a compromised bookmark. Identifying all instances of AVideo, confirming their external reachability and business criticality, and locating the accountable video owner are the immediate first steps. Remediation planning should then prioritize the most exposed or critical deployments.
- Video owners and platform administrators should own.
- Verify external reachability and critical assets.
- Plan remediation based on risk and impact.