Lucene search

K
cvelistMitreCVELIST:CVE-2020-35748
HistoryJan 15, 2021 - 4:50 p.m.

CVE-2020-35748

2021-01-1516:50:42
mitre
www.cve.org
3
cross-site scripting
fv flowplayer video player
wordpress
remote authenticated users
injection
json field

EPSS

0.001

Percentile

26.5%

Cross-site scripting (XSS) vulnerability in models/list-table.php in the FV Flowplayer Video Player plugin before 7.4.37.727 for WordPress allows remote authenticated users to inject arbitrary web script or HTML via the fv_wp_fvvideoplayer_src JSON field in the data parameter.

EPSS

0.001

Percentile

26.5%

Related for CVELIST:CVE-2020-35748