Unauthenticated Stored DOM XSS in AVideo YPTSocket Plugin via Broadcast Metadata
An unauthenticated attacker can inject malicious JavaScript into WebSocket broadcast messages that execute in the browsers of all connected administrators. The vulnerability stems from unsanitized query parameters being stored and propagated to authenticated users without validation.