Vulnerabilities > Wwbn > Avideo > Medium
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2024-01-10 | CVE-2023-47171 | Unspecified vulnerability in Wwbn Avideo 11.6/15Fed957Fb An information disclosure vulnerability exists in the aVideoEncoder.json.php chunkFile path functionality of WWBN AVideo 11.6 and dev master commit 15fed957fb. | 6.5 |
2024-01-10 | CVE-2023-47861 | Cross-site Scripting vulnerability in Wwbn Avideo 11.6/15Fed957Fb A cross-site scripting (xss) vulnerability exists in the channelBody.php user name functionality of WWBN AVideo 11.6 and dev master commit 15fed957fb. | 5.4 |
2024-01-10 | CVE-2023-48728 | Cross-site Scripting vulnerability in Wwbn Avideo 11.6/3C6Bb3Ff A cross-site scripting (xss) vulnerability exists in the functiongetOpenGraph videoName functionality of WWBN AVideo 11.6 and dev master commit 3c6bb3ff. | 6.1 |
2024-01-10 | CVE-2023-48730 | Cross-site Scripting vulnerability in Wwbn Avideo 15Fed957Fb A cross-site scripting (xss) vulnerability exists in the navbarMenuAndLogo.php user name functionality of WWBN AVideo dev master commit 15fed957fb. | 5.4 |
2024-01-10 | CVE-2023-49810 | Improper Restriction of Excessive Authentication Attempts vulnerability in Wwbn Avideo 15Fed957Fb A login attempt restriction bypass vulnerability exists in the checkLoginAttempts functionality of WWBN AVideo dev master commit 15fed957fb. | 6.5 |
2024-01-10 | CVE-2023-49862 | Externally Controlled Reference to a Resource in Another Sphere vulnerability in Wwbn Avideo An information disclosure vulnerability exists in the aVideoEncoderReceiveImage.json.php image upload functionality of WWBN AVideo dev master commit 15fed957fb. | 6.5 |
2024-01-10 | CVE-2023-49863 | Externally Controlled Reference to a Resource in Another Sphere vulnerability in Wwbn Avideo An information disclosure vulnerability exists in the aVideoEncoderReceiveImage.json.php image upload functionality of WWBN AVideo dev master commit 15fed957fb. | 6.5 |
2024-01-10 | CVE-2023-49864 | Externally Controlled Reference to a Resource in Another Sphere vulnerability in Wwbn Avideo Devmastercommit15Fed957Fb An information disclosure vulnerability exists in the aVideoEncoderReceiveImage.json.php image upload functionality of WWBN AVideo dev master commit 15fed957fb. | 6.5 |
2024-01-10 | CVE-2023-50172 | Weak Password Recovery Mechanism for Forgotten Password vulnerability in Wwbn Avideo 15Fed957Fb A recovery notification bypass vulnerability exists in the userRecoverPass.php captcha validation functionality of WWBN AVideo dev master commit 15fed957fb. | 5.3 |
2023-05-08 | CVE-2023-30860 | Cross-site Scripting vulnerability in Wwbn Avideo WWBN AVideo is an open source video platform. | 5.4 |