CVE-2021-25878

Publication date

2021-11-01 11:33:25

Family

mitre

State

PUBLISHED

Description

AVideo/YouPHPTube 10.0 and prior is affected by multiple reflected Cross Script Scripting vulnerabilities via the videoName parameter which allows a remote attacker to steal administrators session cookies or perform actions as an administrator.