What the vulnerability does
01Description
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Foliovision FV Flowplayer Video Player allows Reflected XSS.This issue affects FV Flowplayer Video Player: from n/a through 7.5.45.7212.
Explanation of Vulnerability in Simple Terms
02Summary
FV Flowplayer Video Player versions up to 7.5.45.7212 contain a cross-site scripting vulnerability that allows attackers to inject malicious scripts into video player pages. An attacker can craft a malicious link that, when visited by a site user, executes JavaScript in their browser with access to the page's data. The vulnerability affects the player's handling of user-supplied input.
What an attacker can do
03Attacker Capabilities
Inject and execute JavaScript code in a visitor's browser when they view a page with the vulnerable player.
Potential impact on your site
04Site Impact
Visitors' session cookies, form data, or account credentials could be stolen if they interact with a malicious video player link.
Conditions required to exploit
05Prerequisites
A site visitor must click a malicious link or visit an attacker-controlled page embedding the vulnerable player.
Key dates
06Disclosure timeline
June 3, 2024
CVE published
April 28, 2026
Record updated