Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:7826
HistoryNov 16, 2018 - 7:13 a.m.

Cross-Site Scripting (XSS)

2018-11-1607:13:20
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
10

EPSS

0.011

Percentile

84.5%

jPlayer is vulnerable to cross-site scripting. A remote attacker is able to inject arbitrary Javascript into a victims browser via the jQuery and id parameters in the Flash SWF component. This CVE is different from CVE-2013-1942 and CVE-2013-2023.