No Patch Available: The CVSS 10 Flaw Turning AVideo into an Attacker’s Playground
ID: 2e5e78d0-0f90-573c-8d25-97cb68a2937b
STIX ID: report--2e5e78d0-0f90-573c-8d25-97cb68a2937b
Feed Name: securityonline.info
Threat Score
A critical CVSS 10 vulnerability in AVideo's YPTSocket plugin allows unauthenticated attackers to broadcast JSON messages that are executed via client-side eval() sinks, enabling mass account takeover, remote code execution, site compromise, and persistent malicious payloads; the issue affects versions 29.0 and below with no patch available, and administrators are advised to remove eval() usage, whitelist message fields, and restrict broadcast privileges.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
