GHSA-qvwg-c35p-rqhj

Suggest an improvement
Source
https://github.com/advisories/GHSA-qvwg-c35p-rqhj
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/05/GHSA-qvwg-c35p-rqhj/GHSA-qvwg-c35p-rqhj.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-qvwg-c35p-rqhj
Withdrawn
2024-05-20T18:43:48Z
Published
2024-05-14T18:30:51Z
Modified
2024-12-05T05:32:19Z
Summary
Duplicate Advisory: AVideo cross-site scripting vulnerability in the view/about.php page
Details

Duplicate Advisory

This advisory has been withdrawn because it is a duplicate of GHSA-f98p-2hc5-fm7v. This link is maintained to preserve external references.

Original Description

WWBN AVideo 12.4 is vulnerable to Cross Site Scripting (XSS).

Database specific
{
    "cwe_ids":  [],
    "github_reviewed":  true,
    "github_reviewed_at":  "2024-05-20T18:43:48Z",
    "nvd_published_at":  "2024-05-14T15:39:37Z",
    "severity":  "LOW"
}
References

Affected packages

Packagist / wwbn/avideo

Package

Name
wwbn/avideo
Purl
pkg:composer/wwbn/avideo

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
14.3

Affected versions

10.*
10.4
10.8
Other
11
11.*
11.1
11.1.1
11.5
11.6
12.*
12.4

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/05/GHSA-qvwg-c35p-rqhj/GHSA-qvwg-c35p-rqhj.json"