Back to search
CVE-2013-2023
Published: Aug 15, 2013
Modified: Aug 6, 2024
PUBLISHED
Description
Cross-site scripting (XSS) vulnerability in actionscript/Jplayer.as in the Flash SWF component (jplayer.swf) in jPlayer before 2.3.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, possibly related to incomplete blacklists, a different vulnerability than CVE-2013-1942 and CVE-2013-2022.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
[oss-security] 20130505 Re: CVE-2013-1942 jPlayer 2.2.19 XSS
mailing-list
x_refsource_MLIST
[oss-security] 20130627 Re: Re: CVE-2013-1942 jPlayer 2.2.19 XSS
mailing-list
x_refsource_MLIST
https://github.com/happyworm/jPlayer/issues/162
x_refsource_CONFIRM
[oss-security] 20130411 CVE-2013-1942 jPlayer 2.2.19 XSS
mailing-list
x_refsource_MLIST
http://www.jplayer.org/latest/release-notes/
x_refsource_CONFIRM
[oss-security] 20130704 Re: Re: CVE-2013-1942 jPlayer 2.2.19 XSS
mailing-list
x_refsource_MLIST
20130421 Vulnerabilities in jPlayer
mailing-list
x_refsource_FULLDISC
[oss-security] 20130429 Re: CVE-2013-1942 jPlayer 2.2.19 XSS
mailing-list
x_refsource_MLIST
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now