CVE-2013-7342
Flowplayer HTML5 <5.4.1 - XSS
Title source: llmDescription
Cross-site scripting (XSS) vulnerability in flowplayer.swf in the Flash fallback feature in Flowplayer HTML5 5.4.1 allows remote attackers to inject arbitrary web script or HTML via the callback parameter, a related issue to CVE-2013-7341.
Scores
EPSS
0.0032
EPSS Percentile
54.6%
Details
CWE
CWE-79
Status
published
Products (2)
flowplayer/flowplayer_html5
n/a/n/a
Published
Mar 24, 2014
Tracked Since
Feb 18, 2026