Cross-Site Scripting Vulnerability in WWBN AVideo Products
CVE-2025-53084

9CRITICAL

Key Information:

Vendor

Wwbn

Status
Vendor
CVE Published:
24 July 2025

What is CVE-2025-53084?

A cross-site scripting vulnerability has been identified in the videosList page parameter of WWBN AVideo versions 14.4 and the dev master commit 8a8954ff. This security flaw could enable attackers to execute arbitrary JavaScript by crafting a specially designed HTTP request. Exploitation may occur when unsuspecting users are directed to a compromised webpage, potentially compromising sensitive data or user interactions. It is essential for users of AVideo to remain vigilant and apply any available patches or updates to mitigate the risks associated with this vulnerability.

Affected Version(s)

AVideo 14.4

AVideo dev master commit 8a8954ff

References

CVSS V3.1

Score:
9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Discovered by Claudio Bozzato of Cisco Talos.
.