CVE-2021-39350: FV Flowplayer Video Player <= 7.5.0.727 - 7.5.2.727 Reflected Cross-Site Scripting
The FV Flowplayer Video Player WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the playerid parameter found in the ~/view/stats.php file which allows attackers to inject arbitrary web scripts, in versions 7.5.0.727 - 7.5.2.727.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
FV Flowplayer Video Player (WordPress plugin)to a version that resolves this vulnerability.Fixed in 7.5.3.727
Event History
Frequently Asked Questions
What is CVE-2021-39350?
CVE-2021-39350 is a vulnerability in the FV Flowplayer Video Player WordPress plugin that allows attackers to inject arbitrary web scripts.
What is the severity of CVE-2021-39350?
CVE-2021-39350 has a severity level of medium.
How does the CVE-2021-39350 vulnerability occur?
The CVE-2021-39350 vulnerability is caused by a reflected cross-site scripting (XSS) issue in the player_id parameter of the ~/view/stats.php file.
Which versions of the FV Flowplayer Video Player plugin are affected by CVE-2021-39350?
Versions 7.5.0.727 to 7.5.2.727 of the FV Flowplayer Video Player plugin are affected by CVE-2021-39350.
How can I fix the CVE-2021-39350 vulnerability?
To fix the CVE-2021-39350 vulnerability, update the FV Flowplayer Video Player plugin to a version higher than 7.5.2.727.