Medium severity6.1NVD Advisory· Published May 12, 2023· Updated Jun 17, 2026
CVE-2022-48020
CVE-2022-48020
Description
Vinteo VCC v2.36.4 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the conference parameter. This vulnerability allows attackers to inject arbitrary code which will be executed by the victim user's browser.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- cpe:2.3:a:vinteo:video_core:2.36.4:*:*:*:*:*:*:*
- Vinteo/VCCdescription
Patches
Vulnerability mechanics
References
3- seq.team/en/blog/reflected-cross-site-scripting-xss-in-vinteo-vcc/nvdExploitThird Party Advisory
- seq.team/en/nvdNot Applicable
- www.linkedin.com/in/dmitry-kiryukhin-b5741421b/nvdNot Applicable
News mentions
0No linked articles in our index yet.