Unrated severityNVD Advisory· Published Nov 1, 2021· Updated Aug 3, 2024
CVE-2021-25878
CVE-2021-25878
Description
AVideo/YouPHPTube 10.0 and prior is affected by multiple reflected Cross Script Scripting vulnerabilities via the videoName parameter which allows a remote attacker to steal administrators' session cookies or perform actions as an administrator.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2- AVideo/YouPHPTube/AVideo/YouPHPTubedescription
- Range: <=10.0
Patches
Vulnerability mechanics
References
3- avideoyouphptube.commitrex_refsource_MISC
- synacktiv.commitrex_refsource_MISC
- www.synacktiv.com/sites/default/files/2021-01/YouPHPTube_Multiple_Vulnerabilities.pdfmitrex_refsource_MISC
News mentions
0No linked articles in our index yet.