CVE-2013-7343: XSS
Cross-site scripting (XSS) vulnerability in flowplayer.swf in the Flash fallback feature in Flowplayer HTML5 5.4.3 allows remote attackers to inject arbitrary web script or HTML by using URL encoding within the callback parameter name. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-7342.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-7343?
CVE-2013-7343 is classified as a medium severity vulnerability due to its potential for exploitation via cross-site scripting.
How do I fix CVE-2013-7343?
To fix CVE-2013-7343, upgrade to a version of Flowplayer HTML5 that includes the patch for this vulnerability.
What software is affected by CVE-2013-7343?
CVE-2013-7343 affects Flowplayer HTML5 version 5.4.3.
What type of vulnerability is CVE-2013-7343?
CVE-2013-7343 is a cross-site scripting (XSS) vulnerability.
Can CVE-2013-7343 be exploited remotely?
Yes, CVE-2013-7343 can be exploited remotely by attackers using URL encoding within the callback parameter.