PT-2020-7218 · Longtail Video · Jw Player

Mustlive

·

Published

2020-02-20

·

Updated

2020-02-24

·

CVE-2012-3351

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions LongTail Video JW Player versions through 5.10.2295
Description The issue allows remote attackers to inject arbitrary web script or HTML via the link, logo.link, or aboutlink parameter, or a nested URI scheme name for javascript, asfunction, or vbscript. This enables attackers to execute malicious scripts on the client-side.
Recommendations For versions through 5.10.2295, consider disabling the parameters link, logo.link, and aboutlink to prevent exploitation until a patch is available. Restrict the use of nested URI scheme names for javascript, asfunction, or vbscript in the JW Player to minimize the risk of cross-site scripting attacks.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2012-3351

Affected Products

Jw Player