CVE-2013-7341
Flowplayer Flash <3.2.17 - XSS
Title source: llmDescription
Multiple cross-site scripting (XSS) vulnerabilities in Flowplayer Flash before 3.2.17, as used in Moodle through 2.3.11, 2.4.x before 2.4.9, 2.5.x before 2.5.5, and 2.6.x before 2.6.2, allow remote attackers to inject arbitrary web script or HTML by (1) providing a crafted playerId or (2) referencing an external domain, a related issue to CVE-2013-7342.
References (5)
Scores
EPSS
0.0026
EPSS Percentile
49.0%
Details
CWE
CWE-79
Status
published
Products (50)
moodle/moodle
flowplayer/flowplayer_flash
< 3.2.16
flowplayer/flowplayer_flash
flowplayer/flowplayer_flash
flowplayer/flowplayer_flash
flowplayer/flowplayer_flash
flowplayer/flowplayer_flash
flowplayer/flowplayer_flash
flowplayer/flowplayer_flash
flowplayer/flowplayer_flash
... and 40 more
Published
Mar 24, 2014
Tracked Since
Feb 18, 2026