CVE-2021-25875

Publication date

2021-11-01 11:32:57

Family

mitre

State

PUBLISHED

Description

AVideo/YouPHPTube AVideo/YouPHPTube 10.0 and prior has multiple reflected Cross Script Scripting vulnerabilities via the searchPhrase parameter which allows a remote attacker to steal administrators session cookies or perform actions as an administrator.