What the vulnerability does
01Description
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in FolioVision FV Flowplayer Video Player plugin <= 7.5.32.7212 versions.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
What the vulnerability does
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in FolioVision FV Flowplayer Video Player plugin <= 7.5.32.7212 versions.
Explanation of Vulnerability in Simple Terms
FV Flowplayer Video Player versions up to 7.5.32.7212 contain a cross-site scripting vulnerability that allows attackers to inject malicious scripts into video player pages. An attacker can craft a malicious link that, when visited by a site visitor, executes arbitrary JavaScript in the victim's browser. This can lead to session hijacking, credential theft, or malware distribution.
What an attacker can do
Inject and execute malicious JavaScript in a visitor's browser via a crafted link.
Potential impact on your site
Visitors to your site could have their sessions hijacked, credentials stolen, or be redirected to malware.
Conditions required to exploit
A site visitor must click a malicious link or visit an attacker-controlled page embedding the vulnerable player.
Key dates
External resources
Related vulnerabilities