Vulnerability record · CVE-2022-30690 · published 22 August 2022
CVE-2022-30690: WWBN AVideo image403 reflected XSS via crafted HTTP request
Wwbn · Avideo
AVideo 11.6 and dev master commit 3f7c0364 contain a cross-site scripting flaw in the image403 functionality. A crafted HTTP request causes arbitrary JavaScript execution in the context of the victim's browser. Because the script runs in the site's origin, it can act with the victim's session privileges.
Description
A cross-site scripting (xss) vulnerability exists in the image403 functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. A specially-crafted HTTP request can lead to arbitrary Javascript execution. An attacker can get an authenticated user to send a crafted HTTP request to trigger this vulnerability.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Automated analysis
high priorityThe flaw is remotely reachable with low attack complexity and a very high EPSS score, and public exploit detail exists, though it requires victim interaction and is not in KEV.
What it is
AVideo 11.6 and dev master commit 3f7c0364 contain a cross-site scripting flaw in the image403 functionality. A crafted HTTP request causes arbitrary JavaScript execution in the context of the victim's browser. Because the script runs in the site's origin, it can act with the victim's session privileges.
Impact
An attacker can execute arbitrary JavaScript in an authenticated user's browser, enabling session theft, credential capture, or actions performed as that user. The CVSS scope change (S:C) means impact can extend beyond the vulnerable component.
Attack surface
Reached over the network via a crafted HTTP request to the image403 functionality; no authentication is required by the attacker, but the victim must be authenticated and induced to send the crafted request (UI:R).
Exploitation
Not listed in CISA KEV, but EPSS is very high at 0.839 (99.7th percentile), and the Talos reference is tagged Exploit and Technical Description, indicating public exploit detail exists.
What to do
- Upgrade AVideo to a version containing the fix referenced in the vendor updateDb.v12.0.sql commit, or apply that patch to 11.6 and dev master commit 3f7c0364.
- Encode or sanitize all user-controlled input rendered by the image403 functionality, and apply output encoding appropriate to the HTML context.
- Deploy a Content Security Policy that restricts inline and third-party script execution to limit XSS impact.
- Set session cookies HttpOnly and SameSite, and require re-authentication for sensitive actions.
- Restrict or disable the image403 endpoint if it is not needed.
Detection
- Search web and proxy logs for requests to the image403 endpoint containing script tags, event handlers, or encoded JavaScript payloads.
- Monitor for anomalous JavaScript or unexpected outbound requests originating from AVideo pages in browser or endpoint telemetry.
- Alert on AVideo session cookie reuse from new user agents or IP addresses following image403 requests.
- Review WAF or IDS alerts for XSS signatures targeting AVideo paths.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://github.com/WWBN/AVideo/blob/e04b1cd7062e16564157a82bae389eedd39fa088/updatedb/updateDb.v12.0.sql | Third Party Advisory |
| https://talosintelligence.com/vulnerability_reports/TALOS-2022-1539 | ExploitTechnical DescriptionThird Party Advisory |
| https://github.com/WWBN/AVideo/blob/e04b1cd7062e16564157a82bae389eedd39fa088/updatedb/updateDb.v12.0.sql | Third Party Advisory |
| https://talosintelligence.com/vulnerability_reports/TALOS-2022-1539 | ExploitTechnical DescriptionThird Party Advisory |
Track CVE-2022-30690 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2022-30690), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.