S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2022-32771 Scanner

Detects 'Cross-Site Scripting (XSS)' vulnerability in WWBN AVideo affects v. 11.6 and dev master commit 3f7c0364.

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.3k
Times Used
continuous scan runs
4.4k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2022-32771
6.1
CVSScritical
Exploitable remotely over the internet · no authentication required · user interaction needed.

A cross-site scripting (xss) vulnerability exists in the footer alerts functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. A specially-crafted HTTP request can lead to arbitrary Javascript execution. An attacker can get an authenticated user to send a crafted HTTP request to trigger this vulnerability.This vulnerability arrises from the "success" parameter which is inserted into the document with insufficient sanitization.

Attack Vector
Network
Privileges Req.
None
User Interaction
Required
Affected
AVideoby WWBN
11.6
Updated Aug 22, 2026View on NVD →
Detail

WWBN AVideo is a video hosting and streaming platform used by various websites to provide high-quality video content to their target audience. This platform is popular among media companies and content creators as it offers a range of features to enhance the video viewing experience. With the help of WWBN AVideo, videos can be easily uploaded, managed, and streamed across multiple devices and platforms.

CVE-2022-32771 is a cross-site scripting (XSS) vulnerability that was detected in the footer alerts functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. This particular vulnerability occurs due to insufficient sanitization of the "success" parameter, which can lead to arbitrary Javascript execution. The attacker can exploit this vulnerability by manipulating the crafted HTTP request and getting an authenticated user to send it.

This vulnerability can lead to serious consequences, as an attacker can exploit this security loophole to steal sensitive information such as login credentials, personal data, and banking information. They can also use it to launch phishing attacks, compromise the website's security, and manipulate the website's content. The worst part is that this can happen without the website owner's knowledge, and the attack can take place right under their nose.

In conclusion, digital asset protection is a crucial aspect of online security, and it is imperative to stay vigilant and aware of any potential vulnerabilities that may arise. Thanks to the pro features of s4e.io, you can quickly and easily learn about vulnerabilities that may be present in your digital assets, enabling you to take proactive measures to protect them. Let's come together and keep our digital assets secure!

 

REFERENCES

Solution Advice

To protect your website from this vulnerability, you can take the following precautions:

  • Update your WWBN AVideo software to the latest version available
  • Implement security measures such as firewalls, antivirus software, and intrusion detection systems
  • Use secure coding practices and perform regular security audits
  • Educate your staff members on how to identify and prevent XSS attacks
  • Make use of a security tool like securityforeveryone.com to get regular updates on vulnerabilities in your digital assets.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.