CVE-2018-0642: XSS
Published Sep 7, 2018
·Updated
Cross-site scripting vulnerability in FV Flowplayer Video Player 6.1.2 to 6.6.4 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Affected Software
1 affected component
FolioVision Fv Flowplayer Video Player Wordpress>=6.1.2<=6.6.4
Event History
Sep 7, 2018
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is CVE-2018-0642?
CVE-2018-0642 is a cross-site scripting vulnerability in FV Flowplayer Video Player 6.1.2 to 6.6.4.
2
What is the severity of CVE-2018-0642?
The severity of CVE-2018-0642 is medium (6.1).
3
How does CVE-2018-0642 work?
CVE-2018-0642 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
4
Which software versions are affected by CVE-2018-0642?
CVE-2018-0642 affects FV Flowplayer Video Player versions 6.1.2 to 6.6.4.
5
How can I fix CVE-2018-0642?
To fix CVE-2018-0642, update FV Flowplayer Video Player to a version higher than 6.6.4.