CVE-2021-23414

MEDIUM

video.js < 7.14.3 - Cross-Site Scripting via Track Tag Src Attribute

Title source: llm
STIX 2.1

Description

This affects the package video.js before 7.14.3. The src attribute of track tag allows to bypass HTML escaping and execute arbitrary code.

Scores

CVSS v3 6.5
EPSS 0.0045
EPSS Percentile 63.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N

Details

CWE
CWE-79
Status published
Products (5)
fedoraproject/fedora 35
fedoraproject/fedora 36
fedoraproject/fedora 37
npm/video.js 0 - 7.14.3npm
videojs/video.js < 7.14.3
Published Jul 28, 2021
Tracked Since Feb 18, 2026