Medium severity6.1NVD Advisory· Published Nov 1, 2021· Updated Jul 9, 2026
CVE-2021-25878
CVE-2021-25878
Description
AVideo/YouPHPTube 10.0 and prior is affected by multiple reflected Cross Script Scripting vulnerabilities via the videoName parameter which allows a remote attacker to steal administrators' session cookies or perform actions as an administrator.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4- AVideo/YouPHPTube/AVideo/YouPHPTubedescription
cpe:2.3:a:youphptube:youphptube:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:youphptube:youphptube:*:*:*:*:*:*:*:*range: <=10.0
- (no CPE)range: <=10.0
- Range: <=10.0
Patches
Vulnerability mechanics
References
2- www.synacktiv.com/sites/default/files/2021-01/YouPHPTube_Multiple_Vulnerabilities.pdfnvdExploitVendor Advisory
- synacktiv.comnvdProduct
News mentions
0No linked articles in our index yet.