Skip to content

jplayer Cross Site Scripting vulnerability

Moderate severity GitHub Reviewed Published May 17, 2022 to the GitHub Advisory Database • Updated Apr 2, 2024

Package

npm jplayer (npm)

Affected versions

< 2.3.0

Patched versions

2.3.0

Description

Multiple cross-site scripting (XSS) vulnerabilities in actionscript/Jplayer.as in the Flash SWF component (jplayer.swf) in jPlayer before 2.3.0 allow remote attackers to inject arbitrary web script or HTML via the (1) jQuery or (2) id parameters, a different vulnerability than CVE-2013-1942 and CVE-2013-2023, as demonstrated by using the alert function in the jQuery parameter. NOTE: these are the same parameters as CVE-2013-1942, but the fix for CVE-2013-1942 uses a blacklist for the jQuery parameter.

References

Published by the National Vulnerability Database Aug 17, 2013
Published to the GitHub Advisory Database May 17, 2022
Last updated Apr 2, 2024
Reviewed Apr 2, 2024

Severity

Moderate

Weaknesses

CVE ID

CVE-2013-2022

GHSA ID

GHSA-3jcq-cwr7-6332

Source code

Credits

Checking history
See something to contribute? Suggest improvements for this vulnerability.