jQuery jPlayer – CVE-2013-2023


Kayran has detected multiple cross-site scripting (XSS) vulnerabilities in actionscript/Jplayer.as in the Flash SWF component (jplayer.swf) in the version of the jPlayer you use.
This can happen possibly because there are incomplete blacklists.

This is a different vulnerability than CVE-2013-1942 and CVE-2013-2022.

This vulnerability allows remote attackers to inject arbitrary web scripts or any HTML by using unspecified vectors.


CVSS Version 2.0 – 4.3 Medium


Update the version of the jPlayer being used.
Make sure its version is 2.3.1 or higher.




< Return to all Vulnerabilities

What is a CWE ?

Similar to the article written on CVEs, in this article we will answer the questions :What is CWE ? and, what is the difference between

Read More »