First published: Tue Mar 19 2024(Updated: )
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Foliovision: Making the web work for you FV Flowplayer Video Player allows Stored XSS.This issue affects FV Flowplayer Video Player: from n/a through 7.5.41.7212.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
Flowplayer Video Player | >=7.5.41.7212 | |
WordPress FV Flowplayer Video Player | <=7.5.41.7212 |
Update to 7.5.44.7212 or a higher version.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-29122 is classified as a Stored Cross-site Scripting (XSS) vulnerability.
To fix CVE-2024-29122, upgrade FV Flowplayer Video Player to version 7.5.41.7213 or later.
CVE-2024-29122 affects FV Flowplayer Video Player versions up to 7.5.41.7212.
Stored XSS allows an attacker to inject malicious scripts that persist on the web application and execute when users view affected content.
The vendor for the affected product is Foliovision.