← Vulnerability feed

Vulnerability record · CVE-2022-30690 · published 22 August 2022

CVE-2022-30690: WWBN AVideo image403 reflected XSS via crafted HTTP request

Wwbn · Avideo

AVideo 11.6 and dev master commit 3f7c0364 contain a cross-site scripting flaw in the image403 functionality. A crafted HTTP request causes arbitrary JavaScript execution in the context of the victim's browser. Because the script runs in the site's origin, it can act with the victim's session privileges.

6.1 CVSS 3.1 Medium EPSS 84% · top 0.3% CWE-79 · Cross-site scripting
6.1CVSS 3.1 base score
84%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

A cross-site scripting (xss) vulnerability exists in the image403 functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. A specially-crafted HTTP request can lead to arbitrary Javascript execution. An attacker can get an authenticated user to send a crafted HTTP request to trigger this vulnerability.

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

high priorityThe flaw is remotely reachable with low attack complexity and a very high EPSS score, and public exploit detail exists, though it requires victim interaction and is not in KEV.

What it is

AVideo 11.6 and dev master commit 3f7c0364 contain a cross-site scripting flaw in the image403 functionality. A crafted HTTP request causes arbitrary JavaScript execution in the context of the victim's browser. Because the script runs in the site's origin, it can act with the victim's session privileges.

Impact

An attacker can execute arbitrary JavaScript in an authenticated user's browser, enabling session theft, credential capture, or actions performed as that user. The CVSS scope change (S:C) means impact can extend beyond the vulnerable component.

Attack surface

Reached over the network via a crafted HTTP request to the image403 functionality; no authentication is required by the attacker, but the victim must be authenticated and induced to send the crafted request (UI:R).

Exploitation

Not listed in CISA KEV, but EPSS is very high at 0.839 (99.7th percentile), and the Talos reference is tagged Exploit and Technical Description, indicating public exploit detail exists.

What to do

  • Upgrade AVideo to a version containing the fix referenced in the vendor updateDb.v12.0.sql commit, or apply that patch to 11.6 and dev master commit 3f7c0364.
  • Encode or sanitize all user-controlled input rendered by the image403 functionality, and apply output encoding appropriate to the HTML context.
  • Deploy a Content Security Policy that restricts inline and third-party script execution to limit XSS impact.
  • Set session cookies HttpOnly and SameSite, and require re-authentication for sensitive actions.
  • Restrict or disable the image403 endpoint if it is not needed.

Detection

  • Search web and proxy logs for requests to the image403 endpoint containing script tags, event handlers, or encoded JavaScript payloads.
  • Monitor for anomalous JavaScript or unexpected outbound requests originating from AVideo pages in browser or endpoint telemetry.
  • Alert on AVideo session cookie reuse from new user agents or IP addresses following image403 requests.
  • Review WAF or IDS alerts for XSS signatures targeting AVideo paths.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2022-30690 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2026-40911Wwbn avideo code injection vulnerabilityWWBN AVideo is an open source video platform. In versions 29.0 and prior, the YPTSocket plugin's WebSocket server relays attacker-supplied JSON messa…EPSS 0.86%10.0CVE-2026-33478Wwbn avideo os command injection vulnerabilityWWBN AVideo is an open source video platform. In versions up to and including 26.0, multiple vulnerabilities in AVideo's CloneSite plugin chain toget…EPSS 11%9.9CVE-2022-30547AVideo unzipDirectory path traversal leads to command executionWWBN AVideo 11.6 and dev master commit 3f7c0364 contain a directory traversal flaw in the unzipDirectory functionality. A crafted HTTP request can es…EPSS 64%analysed9.8CVE-2026-33352Wwbn avideo sql injection vulnerabilityWWBN AVideo is an open source video platform. Prior to version 26.0, an unauthenticated SQL injection vulnerability exists in `objects/category.php` …EPSS 0.53%9.8CVE-2026-28501Wwbn avideo sql injection vulnerabilityWWBN AVideo is an open source video platform. Prior to version 24.0, an unauthenticated SQL Injection vulnerability exists in AVideo within the objec…EPSS 1.4%9.8CVE-2026-29093Wwbn avideo improper authentication vulnerabilityWWBN AVideo is an open source video platform. Prior to version 24.0, the official docker-compose.yml publishes the memcached service on host port 112…EPSS 0.62%9.8CVE-2025-48732Wwbn avideo vulnerabilityAn incomplete blacklist exists in the .htaccess sample of WWBN AVideo 14.4 and dev master commit 8a8954ff. A specially crafted HTTP request can lead …EPSS 1.1%9.8CVE-2024-31819Wwbn avideo code injection vulnerabilityAn issue in WWBN AVideo v.12.4 through v.14.2 allows a remote attacker to execute arbitrary code via the systemRootPath parameter of the submitIndex.…EPSS 16%

Source: NIST National Vulnerability Database (record CVE-2022-30690), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.