CVE-2013-2023: XSS
Cross-site scripting (XSS) vulnerability in actionscript/Jplayer.as in the Flash SWF component (jplayer.swf) in jPlayer before 2.3.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, possibly related to incomplete blacklists, a different vulnerability than CVE-2013-1942 and CVE-2013-2022.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-2023?
CVE-2013-2023 is classified as a moderate severity vulnerability due to its potential for cross-site scripting (XSS) attacks.
How do I fix CVE-2013-2023?
To fix CVE-2013-2023, upgrade to jPlayer version 2.3.1 or later, which addresses the XSS vulnerability.
What types of software are affected by CVE-2013-2023?
CVE-2013-2023 affects versions of jPlayer prior to 2.3.1, including earlier beta versions and specific release versions.
What can attackers do by exploiting CVE-2013-2023?
Exploiting CVE-2013-2023 allows attackers to inject arbitrary web script or HTML, which can lead to user data theft or site defacement.
Is CVE-2013-2023 environment-specific?
CVE-2013-2023 is not environment-specific and can affect any web application that uses the vulnerable jPlayer versions.