PT-2020-7218 · Longtail Video · Jw Player
Mustlive
·
Published
2020-02-20
·
Updated
2020-02-24
·
CVE-2012-3351
CVSS v2.0
4.3
Medium
| Vector | AV:N/AC:M/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
LongTail Video JW Player versions through 5.10.2295
Description
The issue allows remote attackers to inject arbitrary web script or HTML via the
link, logo.link, or aboutlink parameter, or a nested URI scheme name for javascript, asfunction, or vbscript. This enables attackers to execute malicious scripts on the client-side.Recommendations
For versions through 5.10.2295, consider disabling the parameters
link, logo.link, and aboutlink to prevent exploitation until a patch is available. Restrict the use of nested URI scheme names for javascript, asfunction, or vbscript in the JW Player to minimize the risk of cross-site scripting attacks.Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Jw Player