First published: Mon Mar 24 2014(Updated: )
Cross-site scripting (XSS) vulnerability in flowplayer.swf in the Flash fallback feature in Flowplayer HTML5 5.4.3 allows remote attackers to inject arbitrary web script or HTML by using URL encoding within the callback parameter name. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-7342.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Flowplayer | =5.4.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-7343 is classified as a medium severity vulnerability due to its potential for exploitation via cross-site scripting.
To fix CVE-2013-7343, upgrade to a version of Flowplayer HTML5 that includes the patch for this vulnerability.
CVE-2013-7343 affects Flowplayer HTML5 version 5.4.3.
CVE-2013-7343 is a cross-site scripting (XSS) vulnerability.
Yes, CVE-2013-7343 can be exploited remotely by attackers using URL encoding within the callback parameter.