Ecosyste.ms: Advisories

An open API service providing security vulnerability metadata for many open source software ecosystems.

Security Advisories: GSA_kwCzR0hTQS0zamNxLWN3cjctNjMzMs4AAecE

jplayer Cross Site Scripting vulnerability

Multiple cross-site scripting (XSS) vulnerabilities in actionscript/Jplayer.as in the Flash SWF component (jplayer.swf) in jPlayer before 2.3.0 allow remote attackers to inject arbitrary web script or HTML via the (1) jQuery or (2) id parameters, a different vulnerability than CVE-2013-1942 and CVE-2013-2023, as demonstrated by using the alert function in the jQuery parameter. NOTE: these are the same parameters as CVE-2013-1942, but the fix for CVE-2013-1942 uses a blacklist for the jQuery parameter.

Permalink: https://github.com/advisories/GHSA-3jcq-cwr7-6332
JSON: https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS0zamNxLWN3cjctNjMzMs4AAecE
Source: GitHub Advisory Database
Origin: Unspecified
Severity: Moderate
Classification: General
Published: almost 2 years ago
Updated: about 1 month ago


Identifiers: GHSA-3jcq-cwr7-6332, CVE-2013-2022
References: Repository: https://github.com/happyworm/jPlayer
Blast Radius: 0.0

Affected Packages

npm:jplayer
Dependent packages: 5
Dependent repositories: 48
Downloads: 232,489 last month
Affected Version Ranges: < 2.3.0
Fixed in: 2.3.0
All affected versions:
All unaffected versions: 2.8.0, 2.8.1, 2.8.3, 2.8.4, 2.9.0, 2.9.1, 2.9.2