PT-2020-7447 · Videolan · Vlc Media Player

Published

2013-08-09

·

Updated

2020-02-03

·

CVE-2013-3565

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions: VLC Media Player versions prior to 2.0.7
Description: The issue concerns multiple cross-site scripting (XSS) vulnerabilities in the HTTP Interface of VLC Media Player. These vulnerabilities allow remote attackers to inject arbitrary web script or HTML. Specifically, the vulnerabilities can be exploited through the command parameter to requests/vlm cmd.xml, the dir parameter to requests/browse.xml, or the URI in a request, which is returned in an error message through share/lua/intf/http.lua.
Recommendations: For versions prior to 2.0.7, update to version 2.0.7 or later to resolve the issue. As a temporary workaround, consider restricting access to the HTTP Interface or disabling the vulnerable parameters, such as command and dir, until a patch is applied. Avoid using the vulnerable URI in requests until the issue is resolved.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2013-3565
MGASA-2013-0241

Affected Products

Vlc Media Player