CVE-2021-39350
FV Flowplayer Video Player <= 7.5.0.727 - 7.5.2.727 Reflected Cross-Site Scripting
Record summary
CVE-2021-39350 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.
Description
The FV Flowplayer Video Player WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the player_id parameter found in the ~/view/stats.php file which allows attackers to inject arbitrary web scripts, in versions 7.5.0.727 - 7.5.2.727.
Exploitation context
Available material
- Nuclei templates
- 1
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Feb 14, 2025 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
FV Flowplayer Video PlayerBrowse FV Flowplayer Video Player / FV Flowplayer Video Player | CVE List | 7.5.0.727 - 7.5.2.727 7.5.2.727 | affected |
Nuclei templates
1ProjectDiscoveryMEDIUMFV Flowplayer Video Player WordPress plugin - Authenticated Cross-Site ScriptingCVSS 6.1
The FV Flowplayer Video Player WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the player_id parameter found in the ~/view/stats.php file which allows attackers to inject arbitrary web scripts in versions 7.5.0.727 - 7.5.2.727.
Impact
Successful exploitation of this vulnerability could allow an authenticated attacker to execute arbitrary JavaScript code in the context of the affected website, potentially leading to session hijacking, defacement, or theft of sensitive information.
Remediation
Update to the latest version of the FV Flowplayer Video Player WordPress plugin to mitigate this vulnerability.
Source: ProjectDiscovery