Security Advisory
CVE-2021-25875
CVE vulnerability detail — eXtreme Datacenter Security Operations
Description
AVideo/YouPHPTube AVideo/YouPHPTube 10.0 and prior has multiple reflected Cross Script Scripting vulnerabilities via the searchPhrase parameter which allows a remote attacker to steal administrators session cookies or perform actions as an administrator.