Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:7829
HistoryNov 16, 2018 - 8:10 a.m.

Cross-Site Scripting (XSS)

2018-11-1608:10:11
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
6

0.002 Low

EPSS

Percentile

52.1%

flowplayer is vulnerable to cross-site scripting. A remote attacker is able to inject arbitrary Javascript into a victim’s browser by via the callback parameter using URL encoding. This vulnerability exists due to an incomplete fix for CVE-2013-7342.

CPENameOperatorVersion
flowplayerle5.4.4

0.002 Low

EPSS

Percentile

52.1%