top of page
perceptive_background_267k.jpg

WWBN AVideo is an open source video platform. In versions 29.0 and prior, the YPTSocket plugin's WebSocket server relays attacker-supplied JSON message bodies t…

Published:

20 april 2026 om 22:00:00

Alert date:

21 april 2026 om 22:04:46

Source:

nvd.nist.gov

Click to open the original link from this advisory

Web Technologies

WWBN AVideo versions 29.0 and prior contain a critical vulnerability in the YPTSocket plugin's WebSocket server. The server relays attacker-supplied JSON messages without sanitization, allowing injection into eval() functions on the client side. Unauthenticated attackers can broadcast arbitrary JavaScript code that executes in all connected users' browsers, including administrators. This leads to universal account takeover, session theft, and privileged action execution. The vulnerability affects the msg and callback fields which are processed by eval() sinks in the client-side script.

Technical details

Mitigation steps:

Affected products:

WWBN AVideo

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page